HPE has released security updates for its Networking Instant On access points after identifying 18 vulnerabilities, including several critical flaws that could allow unauthenticated attackers to execute arbitrary code or commands with privileged operating-system access.
These vulnerabilities are detailed in advisory HPESBNW05150 rev. 1 and affect Instant On AP software versions 3.4.1.0 and earlier. HPE recommends that users upgrade to version 3.4.2.0 or later. Fixes will be automatically applied to eligible devices through the Instant On cloud management portal.
The most severe vulnerabilities are CVE-2026-76721 and CVE-2026-76722, both rated 9.8 out of 10 on the CVSS v3.1 scale. The first vulnerability is an unauthenticated remote buffer overflow flaw that could enable arbitrary code execution as a privileged user.
The second involves uncontrolled format-string vulnerabilities that could allow unauthenticated attackers to execute commands or trigger a denial-of-service condition.
Additionally, there are three other critical flaws, CVE-2026-76723, CVE-2026-76724, and CVE-2026-76725, each carrying a CVSS score of 9.6.
While these require access from adjacent networks rather than direct Internet connectivity, they could still facilitate arbitrary command execution, command injection through the PAPI-acquired command-line interface, or authentication bypass leading to elevated remote code execution.
The advisory also addresses CVE-2026-76726, an unauthenticated remote API authentication-bypass flaw with a CVSS score of 8.1. Under certain conditions beyond the attacker’s control, exploiting this vulnerability could allow unauthorized access to restricted networks.
CVE Details
| CVE | Severity | CVSS | Attack requirement | Impact |
|---|---|---|---|---|
| CVE-2026-76721 | Critical | 9.8 | Unauthenticated, remote | Buffer overflow; privileged RCE |
| CVE-2026-76722 | Critical | 9.8 | Unauthenticated, remote | Format string; command execution/DoS |
| CVE-2026-76723 | Critical | 9.6 | Unauthenticated, adjacent | Buffer overflow; arbitrary commands/RCE |
| CVE-2026-76724 | Critical | 9.6 | Unauthenticated, adjacent | PAPI CLI command injection |
| CVE-2026-76725 | Critical | 9.6 | Unauthenticated, adjacent | Management-protocol authentication bypass; potential RCE |
| CVE-2026-76726 | High | 8.1 | Unauthenticated, remote | API authentication bypass; unauthorized network access |
| CVE-2026-76727 | High | 7.2 | Authenticated, remote, high privilege | Command injection |
| CVE-2026-76728 | High | 7.2 | Authenticated, remote, high privilege | SSRF leading to privileged command execution |
| CVE-2026-76729 | Medium | 6.6 | Authenticated, remote, high privilege | Format string; memory corruption, DoS or RCE |
| CVE-2026-76730 | Medium | 6.5 | Unauthenticated, adjacent | PAPI authentication bypass; unauthorized traffic |
| CVE-2026-76731 | Medium | 6.5 | Unauthenticated, remote | Captive-portal authentication bypass |
| CVE-2026-76732 | Medium | 6.4 | Authenticated, local, high privilege | Local privilege escalation to root |
| CVE-2026-76733 | Medium | 4.9 | Authenticated, remote, admin | API denial of service |
| CVE-2026-76734 | Medium | 4.8 | Unauthenticated, remote | Memory-corruption denial of service |
| CVE-2026-76735 | Medium | 4.1 | Authenticated, local, high privilege | Sensitive-information disclosure |
| CVE-2026-76736 | Low | 3.3 | Authenticated, local, low privilege | Buffer-overflow denial of service |
| CVE-2026-76737 | Low | 3.0 | Authenticated, local, admin | Path traversal; limited file modification/DoS |
| CVE-2026-76738 | Low | 2.7 | Authenticated, remote, admin | API buffer-overflow denial of service |
Organizations should prioritize updating all supported Instant On APs to 3.4.2.0 or later. HPE also recommends isolating web-based management interfaces on a dedicated Layer 2 segment or VLAN, enforcing Layer 3-plus firewall policies, and maintaining activity and resource-use logging.
Deployments running end-of-maintenance releases should be treated as potentially exposed. HPE said it was unaware of public discussion or exploit code targeting these flaws as of the advisory’s September 29 release, but urged customers to patch given the breadth and potential impact of the vulnerabilities.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…