Cyber Security News

HPE Instant On AP Flaws Let Unauthenticated Attackers Execute Arbitrary Commands

HPE has released security updates for its Networking Instant On access points after identifying 18 vulnerabilities, including several critical flaws that could allow unauthenticated attackers to execute arbitrary code or commands with privileged operating-system access.

These vulnerabilities are detailed in advisory HPESBNW05150 rev. 1 and affect Instant On AP software versions 3.4.1.0 and earlier. HPE recommends that users upgrade to version 3.4.2.0 or later. Fixes will be automatically applied to eligible devices through the Instant On cloud management portal.

HPE Instant On AP Flaws

The most severe vulnerabilities are CVE-2026-76721 and CVE-2026-76722, both rated 9.8 out of 10 on the CVSS v3.1 scale. The first vulnerability is an unauthenticated remote buffer overflow flaw that could enable arbitrary code execution as a privileged user.

The second involves uncontrolled format-string vulnerabilities that could allow unauthenticated attackers to execute commands or trigger a denial-of-service condition.

Additionally, there are three other critical flaws, CVE-2026-76723, CVE-2026-76724, and CVE-2026-76725, each carrying a CVSS score of 9.6.

While these require access from adjacent networks rather than direct Internet connectivity, they could still facilitate arbitrary command execution, command injection through the PAPI-acquired command-line interface, or authentication bypass leading to elevated remote code execution.

The advisory also addresses CVE-2026-76726, an unauthenticated remote API authentication-bypass flaw with a CVSS score of 8.1. Under certain conditions beyond the attacker’s control, exploiting this vulnerability could allow unauthorized access to restricted networks.

CVE Details

CVESeverityCVSSAttack requirementImpact
CVE-2026-76721Critical9.8Unauthenticated, remoteBuffer overflow; privileged RCE
CVE-2026-76722Critical9.8Unauthenticated, remoteFormat string; command execution/DoS
CVE-2026-76723Critical9.6Unauthenticated, adjacentBuffer overflow; arbitrary commands/RCE
CVE-2026-76724Critical9.6Unauthenticated, adjacentPAPI CLI command injection
CVE-2026-76725Critical9.6Unauthenticated, adjacentManagement-protocol authentication bypass; potential RCE
CVE-2026-76726High8.1Unauthenticated, remoteAPI authentication bypass; unauthorized network access
CVE-2026-76727High7.2Authenticated, remote, high privilegeCommand injection
CVE-2026-76728High7.2Authenticated, remote, high privilegeSSRF leading to privileged command execution
CVE-2026-76729Medium6.6Authenticated, remote, high privilegeFormat string; memory corruption, DoS or RCE
CVE-2026-76730Medium6.5Unauthenticated, adjacentPAPI authentication bypass; unauthorized traffic
CVE-2026-76731Medium6.5Unauthenticated, remoteCaptive-portal authentication bypass
CVE-2026-76732Medium6.4Authenticated, local, high privilegeLocal privilege escalation to root
CVE-2026-76733Medium4.9Authenticated, remote, adminAPI denial of service
CVE-2026-76734Medium4.8Unauthenticated, remoteMemory-corruption denial of service
CVE-2026-76735Medium4.1Authenticated, local, high privilegeSensitive-information disclosure
CVE-2026-76736Low3.3Authenticated, local, low privilegeBuffer-overflow denial of service
CVE-2026-76737Low3.0Authenticated, local, adminPath traversal; limited file modification/DoS
CVE-2026-76738Low2.7Authenticated, remote, adminAPI buffer-overflow denial of service

Organizations should prioritize updating all supported Instant On APs to 3.4.2.0 or later. HPE also recommends isolating web-based management interfaces on a dedicated Layer 2 segment or VLAN, enforcing Layer 3-plus firewall policies, and maintaining activity and resource-use logging.

Deployments running end-of-maintenance releases should be treated as potentially exposed. HPE said it was unaware of public discussion or exploit code targeting these flaws as of the advisory’s September 29 release, but urged customers to patch given the breadth and potential impact of the vulnerabilities.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

2 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

4 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

4 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

4 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

5 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

6 hours ago