Hpe Hpe

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Hpe product.

RSS Feeds for Hpe security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Hpe products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Hpe Sorted by Most Security Vulnerabilities since 2018

Hpe Arubaos23 vulnerabilities

Hpe Insight Remote Support9 vulnerabilities

Hpe Autopass License Server8 vulnerabilities

Hpe Storeonce System8 vulnerabilities

Hpe Hpux Ntp4 vulnerabilities

Hpe 3par Service Provider2 vulnerabilities

Hpe Arubaos Cx1 vulnerability

By the Year

In 2026 there have been 243 vulnerabilities in Hpe with an average score of 7.1 out of ten. Last year, in 2025 Hpe had 60 security vulnerabilities published. That is, 183 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.01




Year Vulnerabilities Average Score
2026 243 7.08
2025 60 7.09
2024 7 8.81
2023 10 7.84
2022 11 7.44
2021 4 6.15
2020 3 6.90
2019 18 7.63
2018 234 0.00

It may take a day or so for new Hpe vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Hpe Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-76738 Sep 29, 2026
HPE Networking Instant On API Buffer Overflow (CVE-2026-76738) A buffer overflow vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service, which recovers without manual intervention.
CVE-2026-76737 Sep 29, 2026
HPE Networking Instant On: Authenticated Path Traversal in CLI An authenticated path traversal vulnerability exists in the command line interface of HPE Networking Instant On. Successful exploitation could allow an attacker with administrative access to modify a limited set of files on the underlying operating system and to interrupt the normal operation of the affected service.
CVE-2026-76736 Sep 29, 2026
Buffer Overflow in HPE Networking Instant On OS Enables Local Auth Attacker A buffer overflow vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow a low-privilege authenticated local attacker to interrupt the normal operation of the affected service.
CVE-2026-76735 Sep 29, 2026
CVE-2026-76735: Info Disclosure in HPE Networking Instant On OS A sensitive information disclosure vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow an authenticated local attacker with high privileges to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking Instant On, only if certain preconditions outside of the attacker's control are met.
CVE-2026-76734 Sep 29, 2026
Memory Corruption in HPE Instant On Intf Enables Remote DoS A memory corruption vulnerability in the affected interface of HPE Networking Instant On could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service and to access some limited information within the affected component.
CVE-2026-76733 Sep 29, 2026
HPE Networking Instant On API Authenticated DoS A denial-of-service vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service, which resumes without manual intervention.
CVE-2026-76732 Sep 29, 2026
Local Privilege Escalation in HPE Networking Instant ON Daemon A local privilege-escalation vulnerability has been discovered in the affected daemon of HPE Networking Instant ON. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges if certain preconditions are met outside of the attacker's control.
CVE-2026-76731 Sep 29, 2026
CVE-2026-76731: Auth Bypass in HPE Networking Instant On Captive Portal An authentication bypass vulnerability in the captive portal of HPE Networking Instant On could allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain limited access to some data and to make limited changes within the affected component.
CVE-2026-76730 Sep 29, 2026
HPE Instant ON AP Authentication Bypass via PAPI Protocol An authentication bypass vulnerability exists in the PAPI protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to circumvent certain existing authentication mechanisms and send unauthorized network traffic to the target device.
CVE-2026-76729 Sep 29, 2026
HPE Instant ON AP Format String Vulnerability (CVE-2026-76729) A format string vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to cause memory corruption with a modified input. Successful exploitation could allow an attacker to provoke a denial-of-service condition or remote code execution in the affected system function.
CVE-2026-76728 Sep 29, 2026
SSRF in HPE Networking Instant ON AP API allows privileged command exec A vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to conduct a server-side request forgery (SSRF) attack. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
CVE-2026-76727 Sep 29, 2026
HPE Networking Instant ON Command Injection via Authenticated Remote Interface Command injection vulnerabilities exist in the affected interface of HPE Networking Instant ON that could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
CVE-2026-76726 Sep 29, 2026
Auth Bypass in HPE Networking Instant ON API endpoint An authentication bypass vulnerability in the API endpoint of HPE Networking Instant ON could allow an unauthenticated remote attacker to bypass network access controls if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to obtain unauthorized access to restricted networks.
CVE-2026-76725 Sep 29, 2026
HPE Instant ON AP Auth Bypass via Management Protocol (CVE-2026-76725) A vulnerability has been identified in a management protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication controls. Successful exploitation could result in a complete bypass of security restrictions, potentially leading to remote code execution with elevated privileges.
CVE-2026-76724 Sep 29, 2026
Command Injection in HPE Instant ON AP CLI allows Privileged OS Cmd Exec A command injection vulnerability exists in CLI of the affected HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to perform command injection by sending specially crafted packets. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
CVE-2026-76723 Sep 29, 2026
Buffer Overflow in HPE Instant ON APS Interface Causing RCE Buffer overflow vulnerabilities exist in the affected interface of HPE Networking Instant ON APS that could allow an unauthenticated adjacent attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
CVE-2026-76722 Sep 29, 2026
HPE Instant ON AP: Uncontrolled Format String Vulnerability Enabling RCE Uncontrolled Format string vulnerabilities exist in the affected interface of HPE Networking Instant ON APs that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation could result in a Denial-of-service or potential remote code execution.
CVE-2026-76721 Sep 29, 2026
Buffer Overflow in HPE Networking Instant ON Enables RCE Buffer overflow vulnerability exists in the affected interface of HPE Networking Instant ON that could allow an unauthenticated remote attacker to run arbitrary code on the underlying host. Successful exploitation could allow an attacker to execute arbitrary code as a privileged user on the underlying operating system.
CVE-2026-76720 Sep 29, 2026
HPE OneView URL Redirect (Remote Exploit) A vulnerability in HPE OneView can be remotely exploited to cause a URL redirect.
CVE-2026-76719 Sep 29, 2026
Session Hijacking Vulnerability in HPE OneView A security vulnerability in HPE OneView may be exploited remotely to perform session hijacking, data theft or other unauthorized actions.
CVE-2026-76718 Sep 29, 2026
HPE OneView Remote Session Hijacking Vulnerability A potential security vulnerability in HPE OneView can be exploited to allow remote session hijacking or other unauthorized actions.
CVE-2026-76717 Sep 22, 2026
ALE API Info Disclosure in HPE Analytics & Location Engine A vulnerability exists in the Analytics and Location Engine (ALE) API that may allow for the disclosure of sensitive information. An unauthenticated remote attacker could exploit this vulnerability by providing specially crafted input to a specific API endpoint. Successful exploitation could result in the disclosure of sensitive user information, including password hashes, which could be used to facilitate further attacks.
CVE-2026-76716 Sep 22, 2026
Unauth Remote DoS & Escalation in HPE Aruba ALE Multiple vulnerabilities exist in the Analytics and Location Engine (ALE) that may allow for unauthorized access or denial of service. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted input or leveraging improper security configurations. Successful exploitation could result in a denial of service condition or unauthorized access to sensitive information.
CVE-2026-76715 Sep 22, 2026
HPE ALE MitM allows root code exec A vulnerability in an administrative component of Analytics and Location Engine (ALE) is vulnerable to a man-in-the-middle (MitM) attack. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on the affected appliance.
CVE-2026-76714 Sep 22, 2026
HPE Analytics & Loc Engine RCE via Web Interface Vulnerabilities in the Analytics and Location Engine web interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.
CVE-2026-76713 Sep 22, 2026
HPE ALE File System Privileges Escalation via Maintenance Restore A vulnerability exists in the maintenance restore functionality of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an authenticated remote attacker to gain unauthorized access to the file system with root privileges, potentially resulting in full system compromise.
CVE-2026-76712 Sep 22, 2026
Unauthorized Access & DoS in HPE ALE (Analytics & Location Engine) A vulnerability exists in the Analytics and Location Engine (ALE) that may allow for unauthorized access, information disclosure, or denial of service. An unauthenticated remote attacker could exploit the vulnerable system by sending specially crafted input or intercepting network communications. Successful exploitation could result in the disclosure of sensitive information, bypass of security controls, or a denial of service condition on the affected system.
CVE-2026-76710 Sep 22, 2026
HPE ALE: Remote Unauth Info Disclosure via Internal Endpoints A vulnerability exists in the Analytics and Location Engine (ALE) management interface that may allow for the disclosure of sensitive information. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted requests to certain internal endpoints. Successful exploitation could result in the disclosure of sensitive site hierarchy, infrastructure details, and client device information.
CVE-2026-76711 Sep 22, 2026
HPE ALE Socket Input Injection Vulnerability A vulnerability exists in an Analytics and Location Engine (ALE) component where the impacted process improperly processes incoming socket connections. An unauthenticated remote attacker could exploit this vulnerability by providing specially crafted input during the connection process. Successful exploitation could result in unauthorized data injection.
CVE-2026-76709 Sep 22, 2026
HPE ALE Admin Component Remote Write Privilege Escalation A vulnerability exists in the internal administrative component of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to gain unauthorized write access to the file system with elevated privileges, potentially resulting in full system compromise.
CVE-2026-76708 Sep 22, 2026
Hardcoded Default Credentials in HPE ALE Enable Remote Access A vulnerability exists in the Analytics and Location Engine (ALE) where the application and underlying operating system use default, hard-coded credentials for several administrative and system accounts. An unauthenticated remote attacker could exploit this vulnerability by attempting to log in using these known default credentials. Successful exploitation could result in an attacker gaining unauthorized access to the application's management interface and the underlying operating system, potentially leading to full system compromise.
CVE-2026-76706 Sep 15, 2026
Unauthenticated API Disclosure in HPE EdgeConnect SD-WAN Orchestrator A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to obtain sensitive information. Successful exploitation could result in the disclosure of security-relevant configuration details and security feature status, which could be used to facilitate further attacks.
CVE-2026-76707 Sep 15, 2026
HPE EdgeConnect SD-WAN Gateway Memory Disclosure via Adjacent Attack A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to view some system memory contents. Successful exploitation could allow an attacker to gain insight into internal services and workflows, increasing the risk of unauthorized access and elevated privileges when combined with other vulnerabilities.
CVE-2026-76705 Sep 15, 2026
HPE EdgeConnect SD-WAN Gateway API Buffer Overflow CVE-2026-76705 A buffer overflow vulnerability exists in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with Admin privilege to execute arbitrary commands on the underlying operating system.
CVE-2026-76704 Sep 15, 2026
EdgeConnect Orchestrator XSS: Auth Exec Arbitrary Script Code A vulnerability in the web-based management interface of the EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to execute arbitrary script code in a victim's browser in the context of the affected interface. Successful exploitation could allow an attacker to access sensitive information, potentially affecting the confidentiality and integrity of the data processed by the application.
CVE-2026-76703 Sep 15, 2026
Buffer Overflow in HPE EdgeConnect SD-WAN Gateway Web UI DoS A buffer overflow vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways that could allow an authenticated attacker with administrative access to cause a denial of service. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an unstable system state.
CVE-2026-76702 Sep 15, 2026
A vulnerability in the operating system of HPE Networking EdgeConnect SD-WAN Gateways could A vulnerability in the operating system of HPE Networking EdgeConnect SD-WAN Gateways could allow an authenticated local attacker to cause a denial-of-service. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an unstable system state.
CVE-2026-76700 Sep 15, 2026
Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to cause a denial-of-service Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to cause a denial-of-service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service.
CVE-2026-76701 Sep 15, 2026
A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to access sensitive information. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking EdgeConnect SD-WAN Gateways.
CVE-2026-76699 Sep 15, 2026
A buffer overflow vulnerability exists in a system service within the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways A buffer overflow vulnerability exists in a system service within the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated adjacent attacker to cause a denial-of-service. Successful exploitation could allow an attacker to crash the impacted service and temporarily disrupting network operations.
CVE-2026-76698 Sep 15, 2026
A command injection vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways A command injection vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways. An authenticated remote attacker with limited access privileges could exploit this vulnerability through specially crafted input. Successful exploitation, under certain conditions, could result in the execution of arbitrary commands with elevated privileges or a denial-of-service condition on the affected appliance.
CVE-2026-76697 Sep 15, 2026
A vulnerability in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways could A vulnerability in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking EdgeConnect SD-WAN Gateways.
CVE-2026-76696 Sep 15, 2026
A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to crash the system, preventing it from rebooting without manual intervention and disrupting network operations.
CVE-2026-76695 Sep 15, 2026
Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to send specially crafted packets to the affected service. Successful exploitation could allow an attacker to affect the integrity and availability of the affected service.
CVE-2026-76694 Sep 15, 2026
A privilege escalation vulnerability exists in the command line interface of HPE Networking EdgeConnect SD-WAN Gateways A privilege escalation vulnerability exists in the command line interface of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with high privileges to escalate privileges beyond their authorized level, and execute arbitrary code on a vulnerable system.
CVE-2026-76693 Sep 15, 2026
A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to cause a denial-of-service against certain services running on impacted Gateways.
CVE-2026-76692 Sep 15, 2026
A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to obtain limited information from memory and disrupt the normal operation of the affected service. Successful exploitation could result in a denial of service (system crash) or the disclosure of uninitialized stack memory.
CVE-2026-76691 Sep 15, 2026
Buffer overflow vulnerabilities exist in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways Buffer overflow vulnerabilities exist in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker to execute arbitrary commands as a privileged user on the underlying operating system.
CVE-2026-76690 Sep 15, 2026
A vulnerability exists in a component of the HPE Networking EdgeConnect SD-WAN Gateways that may allow for arbitrary command execution A vulnerability exists in a component of the HPE Networking EdgeConnect SD-WAN Gateways that may allow for arbitrary command execution. An authenticated remote attacker could exploit this vulnerability by providing a specially crafted input to the affected component. Successful exploitation could result in remote code execution as root.
CVE-2026-76688 Sep 15, 2026
Vulnerabilities have been identified in the web-based management interface of EdgeConnect SD-WAN Orchestrator Vulnerabilities have been identified in the web-based management interface of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the EdgeConnect SD-WAN Orchestrator host.
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.