StorageGRID
NetApp- Product type
- Other
- Catalog vulnerabilities
- 74
Severity across 8 analyzed records
en
Verify to analyze this security profile
As of 09/20/2026, within CyStack's analyzed data, StorageGRID has 1 security vulnerability published in the last 90 days. Of these, 0 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of StorageGRID and determine which vulnerabilities affect that version.
| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-22056CVE-2026-22056 Denial of Service Vulnerability in StorageGRID (formerly StorageGRID Webscale) | Exploitation statusNot known exploited | FixNot confirmed | Published08/28/2026 | SeverityLow |
CVE-2026-22051 | Exploitation statusNot known exploited | FixYes | Published04/20/2026 | SeverityLow |
CVE-2025-26517CVE-2025-26517 Privilege Escalation Vulnerability in StorageGRID (formerly StorageGRID Webscale) | Exploitation statusNot known exploited | FixYes | Published09/19/2025 | SeverityMedium |
CVE-2025-26516CVE-2025-26516 Denial of Service Vulnerability in StorageGRID (formerly StorageGRID Webscale) | Exploitation statusNot known exploited | FixYes | Published09/19/2025 | SeverityMedium |
CVE-2025-26515CVE-2025-26515 Server-Side Request Forgery Vulnerability in StorageGRID (formerly StorageGRID Webscale) | Exploitation statusNot known exploited | FixYes | Published09/19/2025 | SeverityHigh |
CVE-2025-26514CVE-2025-26514 Reflected Cross-Site Scripting Vulnerability in StorageGRID (formerly StorageGRID Webscale) | Exploitation statusNot known exploited | FixYes | Published09/19/2025 | SeverityMedium |
CVE-2025-25292Ruby SAML vulnerable to SAML authentication bypass due to namespace handling (parser differential) | Exploitation statusNot known exploited | FixNot confirmed | Published03/12/2025 | SeverityCritical |
CVE-2025-25291ruby-saml vulnerable to SAML authentication bypass due to DOCTYPE handling (parser differential) | Exploitation statusPublic exploit | FixNot confirmed | Published03/12/2025 | SeverityCritical |
CVE-2024-21994CVE-2024-21994 Denial of Service Vulnerability in StorageGRID (formerly StorageGRID Webscale) | Exploitation statusNot known exploited | FixYes | Published11/08/2024 | SeverityMedium |
CVE-2024-21988CVE-2024-21988 SSH Cryptographic Implementation Vulnerability in StorageGRID (formerly StorageGRID Webscale) | Exploitation statusNot known exploited | FixYes | Published06/14/2024 | SeverityMedium |
CVE-2024-21984Reflected Cross-Site Scripting Vulnerability in StorageGRID (formerly StorageGRID Webscale) | Exploitation statusNot known exploited | FixYes | Published02/16/2024 | SeverityMedium |
CVE-2024-21983Denial of Service Vulnerability in StorageGRID (formerly StorageGRID Webscale) | Exploitation statusNot known exploited | FixYes | Published02/16/2024 | SeverityMedium |
CVE-2023-27318Denial of Service Vulnerability in StorageGRID (formerly StorageGRID Webscale) | Exploitation statusNot known exploited | FixYes | Published02/05/2024 | SeverityMedium |
CVE-2022-38734 | Exploitation statusNot known exploited | FixNot confirmed | Published03/02/2023 | SeverityUnknown |
CVE-2022-23238 | Exploitation statusNot confirmed | FixNot confirmed | Published08/09/2022 | SeverityUnknown |
CVE-2022-37434 | Exploitation statusPublic exploit | FixNot confirmed | Published08/05/2022 | SeverityCritical |
CVE-2022-1678 | Exploitation statusNot confirmed | FixNot confirmed | Published05/25/2022 | SeverityMedium |
CVE-2022-0778Infinite loop in BN_mod_sqrt() reachable when parsing certificates | Exploitation statusNot known exploited | FixYes | Published03/15/2022 | SeverityHigh |
CVE-2022-23233 | Exploitation statusNot confirmed | FixNot confirmed | Published03/04/2022 | SeverityUnknown |
CVE-2022-23232 | Exploitation statusNot confirmed | FixNot confirmed | Published03/04/2022 | SeverityUnknown |
CVE-2022-23773 | Exploitation statusNot confirmed | FixNot confirmed | Published02/11/2022 | SeverityUnknown |
CVE-2022-23772 | Exploitation statusNot confirmed | FixNot confirmed | Published02/11/2022 | SeverityUnknown |
CVE-2022-23806 | Exploitation statusNot confirmed | FixNot confirmed | Published02/11/2022 | SeverityUnknown |
CVE-2021-27006 | Exploitation statusNot confirmed | FixNot confirmed | Published12/23/2021 | SeverityUnknown |
CVE-2021-40438mod_proxy SSRF | Exploitation statusKEV | FixNot confirmed | Published09/16/2021 | SeverityCritical |
CVE-2021-39275ap_escape_quotes buffer overflow | Exploitation statusNot confirmed | FixNot confirmed | Published09/16/2021 | SeverityUnknown |
CVE-2021-36160mod_proxy_uwsgi out of bound read | Exploitation statusNot confirmed | FixNot confirmed | Published09/16/2021 | SeverityUnknown |
CVE-2021-34798NULL pointer dereference in httpd core | Exploitation statusNot confirmed | FixNot confirmed | Published09/16/2021 | SeverityUnknown |
CVE-2021-34558 | Exploitation statusNot confirmed | FixNot confirmed | Published07/15/2021 | SeverityUnknown |
CVE-2021-3450CA certificate check bypass with X509_V_FLAG_X509_STRICT | Exploitation statusNot confirmed | FixYes | Published03/25/2021 | SeverityUnknown |
CVE-2021-3449NULL pointer deref in signature_algorithms processing | Exploitation statusNot confirmed | FixYes | Published03/25/2021 | SeverityUnknown |
CVE-2021-3114 | Exploitation statusNot confirmed | FixNot confirmed | Published01/26/2021 | SeverityUnknown |
CVE-2021-3115 | Exploitation statusNot confirmed | FixNot confirmed | Published01/26/2021 | SeverityUnknown |
CVE-2020-16166 | Exploitation statusNot confirmed | FixNot confirmed | Published07/30/2020 | SeverityUnknown |
CVE-2020-14664 | Exploitation statusNot known exploited | FixNot confirmed | Published07/15/2020 | SeverityHigh |
CVE-2020-14593 | Exploitation statusNot known exploited | FixNot confirmed | Published07/15/2020 | SeverityHigh |
CVE-2020-14578 | Exploitation statusNot known exploited | FixNot confirmed | Published07/15/2020 | SeverityLow |
CVE-2020-14581 | Exploitation statusNot known exploited | FixNot confirmed | Published07/15/2020 | SeverityLow |
CVE-2020-14577 | Exploitation statusNot known exploited | FixNot confirmed | Published07/15/2020 | SeverityLow |
CVE-2020-14583 | Exploitation statusNot known exploited | FixNot confirmed | Published07/15/2020 | SeverityHigh |
CVE-2020-14579 | Exploitation statusNot known exploited | FixNot confirmed | Published07/15/2020 | SeverityLow |
CVE-2020-14556 | Exploitation statusNot known exploited | FixNot confirmed | Published07/15/2020 | SeverityMedium |
CVE-2020-2830 | Exploitation statusNot known exploited | FixNot confirmed | Published04/15/2020 | SeverityMedium |
CVE-2020-2803 | Exploitation statusNot known exploited | FixNot confirmed | Published04/15/2020 | SeverityHigh |
CVE-2020-2805 | Exploitation statusNot known exploited | FixNot confirmed | Published04/15/2020 | SeverityHigh |
CVE-2020-2816 | Exploitation statusNot known exploited | FixNot confirmed | Published04/15/2020 | SeverityHigh |
CVE-2020-2781 | Exploitation statusNot known exploited | FixNot confirmed | Published04/15/2020 | SeverityMedium |
CVE-2020-2800 | Exploitation statusNot known exploited | FixNot confirmed | Published04/15/2020 | SeverityMedium |
CVE-2020-2778 | Exploitation statusNot known exploited | FixNot confirmed | Published04/15/2020 | SeverityLow |
CVE-2020-2767 | Exploitation statusNot known exploited | FixNot confirmed | Published04/15/2020 | SeverityMedium |
CVE-2020-2773 | Exploitation statusNot known exploited | FixNot confirmed | Published04/15/2020 | SeverityLow |
CVE-2020-2757 | Exploitation statusNot known exploited | FixNot confirmed | Published04/15/2020 | SeverityLow |
CVE-2020-2755 | Exploitation statusNot known exploited | FixNot confirmed | Published04/15/2020 | SeverityLow |
CVE-2020-2754 | Exploitation statusNot known exploited | FixNot confirmed | Published04/15/2020 | SeverityLow |
CVE-2020-2756 | Exploitation statusNot known exploited | FixNot confirmed | Published04/15/2020 | SeverityLow |
CVE-2020-8571 | Exploitation statusNot confirmed | FixNot confirmed | Published03/13/2020 | SeverityUnknown |
CVE-2019-15590-byte record padding oracle | Exploitation statusNot confirmed | FixYes | Published02/27/2019 | SeverityUnknown |
CVE-2018-2825 | Exploitation statusNot known exploited | FixNot confirmed | Published04/19/2018 | SeverityHigh |
CVE-2018-2826 | Exploitation statusNot known exploited | FixNot confirmed | Published04/19/2018 | SeverityHigh |
CVE-2018-1303 | Exploitation statusNot confirmed | FixNot confirmed | Published03/26/2018 | SeverityUnknown |
CVE-2018-1302 | Exploitation statusNot confirmed | FixNot confirmed | Published03/26/2018 | SeverityUnknown |
CVE-2018-1312 | Exploitation statusNot confirmed | FixNot confirmed | Published03/26/2018 | SeverityUnknown |
CVE-2018-1283 | Exploitation statusNot confirmed | FixNot confirmed | Published03/26/2018 | SeverityUnknown |
CVE-2017-15710 | Exploitation statusNot confirmed | FixNot confirmed | Published03/26/2018 | SeverityUnknown |
CVE-2017-15715 | Exploitation statusNot confirmed | FixNot confirmed | Published03/26/2018 | SeverityUnknown |
CVE-2018-1301 | Exploitation statusNot confirmed | FixNot confirmed | Published03/26/2018 | SeverityUnknown |
CVE-2016-10708 | Exploitation statusNot known exploited | FixNot confirmed | Published01/21/2018 | SeverityHigh |
CVE-2018-2638 | Exploitation statusNot known exploited | FixNot confirmed | Published01/18/2018 | SeverityUnknown |
CVE-2018-2581 | Exploitation statusNot known exploited | FixNot confirmed | Published01/18/2018 | SeverityUnknown |
CVE-2018-2627 | Exploitation statusNot known exploited | FixNot confirmed | Published01/18/2018 | SeverityHigh |
CVE-2016-8610 | Exploitation statusNot confirmed | FixNot confirmed | Published11/13/2017 | SeverityUnknown |
CVE-2017-7668 | Exploitation statusNot confirmed | FixNot confirmed | Published06/20/2017 | SeverityUnknown |
CVE-2017-3167 | Exploitation statusNot confirmed | FixNot confirmed | Published06/20/2017 | SeverityUnknown |
CVE-2016-3427 | Exploitation statusKEV | FixNot confirmed | Published04/21/2016 | SeverityCritical |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan