Attackers can bypass critical security policies within NetApp's Active IQ ecosystem by exploiting vulnerabilities in Config Advisor and OneCollect.
Vulnerable Active IQ Components
NetApp has identified security flaws affecting specific versions of its management tools. Active IQ Config Advisor versions prior to 6.7.4 and Active IQ OneCollect versions prior to 2.7.4 are susceptible to these exploits. These vulnerabilities, tracked as CVE-2026-22054 and CVE-2026-22055, provide a direct path for unauthorized actors to circumvent the security policies intended to protect these systems.
Remediation and Patching
Addressing these flaws requires immediate attention to NetApp's official security advisories. Administrators should consult NetApp security bulletins NTAP-20260603-0001 and NTAP-20260603-0002 to obtain the necessary patches. Upgrading to the fixed versions—6.7.4 for Config Advisor and 2.7.4 for OneCollect—is the primary method for neutralizing the risk of a policy bypass.
Securing these management tools prevents attackers from undermining the broader security posture of the NetApp infrastructure.
Source: Multiples vulnérabilités dans les produits NetApp (04 juin 2026)
Domain: cert.ssi.gouv.fr
Comments load interactively on the live page.