Hpe
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Hpe product.
RSS Feeds for Hpe security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Hpe products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Hpe Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 174 vulnerabilities in Hpe with an average score of 7.0 out of ten. Last year, in 2025 Hpe had 60 security vulnerabilities published. That is, 114 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.07
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 174 | 7.03 |
| 2025 | 60 | 7.09 |
| 2024 | 7 | 8.81 |
| 2023 | 10 | 7.84 |
| 2022 | 11 | 7.44 |
| 2021 | 4 | 6.15 |
| 2020 | 3 | 6.90 |
| 2019 | 18 | 7.63 |
| 2018 | 234 | 0.00 |
It may take a day or so for new Hpe vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Hpe Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-73785 | Sep 11, 2026 |
Remote Unauth DoS in HPE IceWall Federation Agent/ProxyA potential security vulnerability in HPE IceWall Federation Agent and Proxy could allow a remote unauthenticated attacker to cause a denial of service (DoS). |
|
| CVE-2026-73784 | Sep 11, 2026 |
HPE IceWall SAML Response Tampering Allows User ImpersonationA potential security vulnerability in HPE IceWall products could be exploited to tamper SAML response, allowing an attacker to impersonate another user. |
|
| CVE-2026-73789 | Sep 09, 2026 |
Unauthenticated Remote Exploit of HP CPPM Guest Account Web UIA vulnerability in the web-based management interface of CPPM guest account management services could allow an unauthenticated remote attacker to manipulate account settings. Successful exploitation could allow an attacker to extend network access beyond policy limits, leading to unauthorized prolonged use of network resources. |
|
| CVE-2026-73788 | Sep 09, 2026 |
ClearPass OnGuard Agent PrivEsc VulnerabilityA vulnerability in the ClearPass OnGuard agent could allow an authenticated remote attacker to elevate their own privileges on a vulnerable ClearPass OnGuard deployment. Successful exploitation could allow an attacker to obtain root privileges, leading to potentially unauthorized operation of the vulnerable system. |
|
| CVE-2026-73787 | Sep 09, 2026 |
HPE CPPM RCE via Web Authenticated Directory DisclosureA vulnerability in the CPPM web interface could allow an authenticated remote attacker to access directory information on a vulnerable system. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. |
|
| CVE-2026-73786 | Sep 09, 2026 |
HPE CPPM Web UI DoS VulnerabilityA vulnerability in the web-based management interface of CPPM could allow an unauthenticated remote attacker to conduct a Denial-of-Service (DoS) attack. Successful exploitation could allow an attacker to cause instability and degrade performance of the vulnerable CPPM server. |
|
| CVE-2026-73769 | Sep 09, 2026 |
HPE CPPM RCE via Authenticated Web UIA vulnerability in the web-based management interface of vulnerable CPPM systems could allow an authenticated remote attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. |
|
| CVE-2026-73783 | Sep 01, 2026 |
AOS-CX API endpoint stack overflow leads to DOSStack overflow vulnerabilities exist in an API endpoint of AOS-CX. Successful exploitation could allow an authenticated malicious actor to cause a denial-of-service condition on the affected system. |
|
| CVE-2026-73782 | Sep 01, 2026 |
Format String Vulnerability in AOS-CX CLI Enables Unauth RCEA format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticated remote code execution. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system. |
|
| CVE-2026-73781 | Sep 01, 2026 |
HPE AOS-CX Authenticated Remote Stored XSS in Web UIA vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface. |
|
| CVE-2026-73780 | Sep 01, 2026 |
AOS-CX Web UI CSRF Enables Remote ExecutionA vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Request Forgery (CSRF) protection. This could allow a remote unauthenticated attacker to execute arbitrary input against the affected interface if the attacker can convince an authenticated user of the interface to interact with a specially crafted URL. |
|
| CVE-2026-73779 | Sep 01, 2026 |
Unauth Remote Bypass in HPE AOS-CX Switch OSVulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could compromise system integrity and further expose sensitive information. |
|
| CVE-2026-73778 | Sep 01, 2026 |
HPE Credential Manager: Factory-Default Password Allows Remote Admin AccessA vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthenticated remote attacker could exploit this vulnerability on a device in its factory-default or post-ZTP state before any administrator has configured credentials by providing a predictable factory-default password. Successful exploitation could result in full administrative control of the affected device during the initial setup process. |
|
| CVE-2026-73777 | Sep 01, 2026 |
Unauthenticated API Auth Bypass in HPE AOS-CX SwitchesVulnerabilities have been identified in the API endpoint of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. |
|
| CVE-2026-73776 | Sep 01, 2026 |
AOS-CX CLI Sig Verify Bypass RCE on OSA signature verification bypass vulnerability exists in the command line interface of AOS-CX. Successful exploitation could allow an authenticated malicious actor with administrative privileges to execute arbitrary code on the underlying operating system, when certain pre-conditions outside of the attackerâs control are met. |
|
| CVE-2026-73775 | Sep 01, 2026 |
AOS-CX API Endpoint Info Disclosure via Low-privilege AuthVulnerabilities in the API endpoint of AOS-CX could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by AOS-CX. |
|
| CVE-2026-73774 | Sep 01, 2026 |
AOS-CX OS Buffer Overflow Enables Unauth DisclosureA buffer overflow vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated disclosure of sensitive information by sending specially crafted packets to the affected system. Successful exploitation of this vulnerability could result in limited disclosure or modification of information and disruption of the affected system. |
|
| CVE-2026-73773 | Sep 01, 2026 |
AOS-CX API endpoint Unauthenticated DoSAn unauthenticated Denial-of-Service (DoS) vulnerability exists in the API endpoint of AOS-CX. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected service. |
|
| CVE-2026-73772 | Sep 01, 2026 |
AOS-CX Buffer Overflow in Service Enables Unauth DoSBuffer overflow vulnerabilities exist in an underlying service of AOS-CX that could lead to an unauthenticated denial-of-service condition by sending specially crafted packets to the affected device. Successful exploitation of these vulnerabilities results in a disruption of normal operation of the underlying operating system. |
|
| CVE-2026-73771 | Sep 01, 2026 |
HPE AOS-CX Auth Bypass in Management Interface (CVE-2026-73771)An authentication vulnerability exists in the AOS-CX management interface and API that may allow improper authentication processing. An unauthenticated remote attacker could exploit this vulnerability under specific conditions to bypass authentication controls or exhaust system resources. Successful exploitation could result in unauthorized access or denial of service affecting the management interface. |
|
| CVE-2026-73770 | Sep 01, 2026 |
Authenticated Arbitrary File Write in HPE Aruba AOS-CX OSAn authenticated arbitrary file write vulnerability exists in AOS-CX. Successful exploitation could allow an authenticated malicious actor, under specific conditions outside the attacker's control and following a required action by another user, to create or modify arbitrary files and execute arbitrary commands as a privileged user on the underlying operating system. |
|
| CVE-2026-73768 | Sep 01, 2026 |
Aruba AOS-CX CLI: Incorrect Input Processing Enables Root ExecA vulnerability exists in the command line interface of AOS-CX that may allow for improper processing of malformed input. Successful exploitation could result in the execution of arbitrary commands with root privileges. |
|
| CVE-2026-73767 | Sep 01, 2026 |
AOS-CX CLI Authenticated Cmd Injection Enables Privileged OS ExecAuthenticated command injection vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. |
|
| CVE-2026-73766 | Sep 01, 2026 |
AOS-CX API Command Injection Allowing Privileged OS ExecCommand injection vulnerabilities in the API endpoint of AOS-CX could allow an authenticated remote attacker with administrative privileges to inject arbitrary commands. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system. |
|
| CVE-2026-73765 | Sep 01, 2026 |
Path Traversal in AOS-CX API Enables Remote Code ExecAuthenticated path traversal vulnerabilities exist in API endpoints of AOS-CX. Successful exploitation of these vulnerabilities allows an attacker to write arbitrary files to the underlying operating system, which could lead to remote code execution. |
|
| CVE-2026-73764 | Sep 01, 2026 |
AOS-CX OS Auth Bypass via Unauthenticated Remote ActorVulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable unauthorized modification of affected resources and limited disruption of affected services. |
|
| CVE-2026-73763 | Sep 01, 2026 |
Unauth RCE in HPE iLO MGMT ComponentA vulnerability exists in a management component that could allow an unauthenticated adjacent attacker to execute arbitrary commands. Successful exploitation could result in remote execution of arbitrary commands in the context of the affected utility. |
|
| CVE-2026-73762 | Sep 01, 2026 |
Remote Access Control Bypass via AOS-CX API EndpointA vulnerability has been identified in the API endpoint of AOS-CX that could allow a remote actor to circumvent existing access controls. In some cases this could enable unauthorized access to management functionality that should be restricted by the configured access control policy. |
|
| CVE-2026-73761 | Sep 01, 2026 |
AOS-CX OS OOB Read Leading to Info Disclosure via PacketAn out-of-bounds read vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated information disclosure by sending a specially crafted packet. Successful exploitation of this vulnerability results in the ability to disclose sensitive information from the underlying operating system. |
|
| CVE-2026-73760 | Sep 01, 2026 |
AOS-CX Path Traversal: Authenticated Access to OS FilesAn authenticated Path Traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to read arbitrary files from the web-based management interface of the underlying operating system, which could lead to remote unauthorized access to files. |
|
| CVE-2026-73759 | Sep 01, 2026 |
AOS-CX DoS via Crafted Packets (Unauthenticated Remote)Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-of-service condition by sending specially crafted packets. Successful exploitation of these vulnerabilities results in disruption of normal operation on affected devices. |
|
| CVE-2026-73758 | Sep 01, 2026 |
Privilege Escalation via API Endpoint in AOS-CX (HPE)A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulnerable system. |
|
| CVE-2026-73757 | Sep 01, 2026 |
ArubaOS-CX SSRF via WebMgmt InterfaceA vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a server-side request forgery (SSRF) attack. A successful exploit allows an attacker to enumerate information about the internal structure of the AOS-CX host, leading to potential disclosure and limited modification of sensitive information. |
|
| CVE-2026-73756 | Sep 01, 2026 |
Remote API Endpoint Info Disclosure in HPE AOS-CX via MITMA vulnerability in an API endpoint of AOS-CX could allow a remote unauthenticated attacker to obtain sensitive information via a man-in-the-middle attack. Successful exploitation allows an attacker to retrieve data which could be used to further compromise the confidentiality of the affected system. |
|
| CVE-2026-73755 | Sep 01, 2026 |
AOS-CX API Privilege Escalation via Authenticated Operator AccessA privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low-privilege operator user, after a required user action, to access sensitive information from the vulnerable system. |
|
| CVE-2026-73754 | Sep 01, 2026 |
CVE-2026-73754: Authenticated DoS via AOS-CX CLIDenial-of-service vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation could allow an authenticated user to disrupt the normal operation of a vulnerable system. |
|
| CVE-2026-73753 | Sep 01, 2026 |
HPE OneView CommandLine Privilege Escalation (CVE202673753)Exploitation through affected command-line operations could allow an authenticated low-privileged user to execute arbitrary commands as a privileged user on the underlying operating system. |
|
| CVE-2026-73752 | Sep 01, 2026 |
AOS-CX API Arbitrary File Write VulnerabilityAn unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. Successful exploitation of this vulnerability allows an attacker to write arbitrary files to the underlying operating system, which could lead to remote code execution. |
|
| CVE-2026-73751 | Sep 01, 2026 |
Command Injection via Web UI in HPE iLO Low-Priv AuthAn authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system. |
|
| CVE-2026-73750 | Sep 01, 2026 |
HPE Auth Module Improper Input Handling: DoS/Remote Code ExecVulnerabilities exist in the authentication module that may improperly process malformed or truncated input. An authenticated remote attacker could exploit these vulnerabilities by providing specially crafted input from a compromised or hostile authentication server. Successful exploitation could result in a Denial-of-Service or potential remote code execution with elevated privileges. |
|
| CVE-2026-73749 | Sep 01, 2026 |
ArubaOSCX Daemon Unauth RCE via Malformed PacketsMultiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service. Successful exploitation could result in remote code execution with elevated privileges. |
|
| CVE-2026-76658 | Sep 01, 2026 |
Unauth SSH Exploit in HPE Networking Fabric Composer SSH DaemonA vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system leading to complete system compromise. |
|
| CVE-2026-76657 | Sep 01, 2026 |
HPE Networking Fabric Composer un-auth RCE via API auth bypassVulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the HPE Networking Fabric Composer host. |
|
| CVE-2026-73748 | Sep 01, 2026 |
HPE Networking Fabric Composer Credentials Leak via Cleartext InterfaceA vulnerability in the affected interface of HPE Networking Fabric Composer allows an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking Fabric Composer. |
|
| CVE-2026-73747 | Sep 01, 2026 |
Local Privilege Escalation in HPE Networking Fabric ComposerA local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user with local access to elevate their user privileges and make limited modifications on the affected system. |
|
| CVE-2026-73746 | Sep 01, 2026 |
HPE Networking Fabric Composer API DoS Authenticated LowPrivilege OperatorA denial-of-service vulnerability exists in the API of HPE Networking Fabric Composer that could allow an authenticated low privilege operator user to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service. |
|
| CVE-2026-73744 | Sep 01, 2026 |
HPE Networking Fabric Composer Web UI DoS via Authenticated Low Privilege UserA denial-of-service vulnerability exists in the web-based management interface of HPE Networking Fabric Composer that could allow an authenticated low privilege operator user to cause a denial of service. Successful exploitation could allow an attacker to disrupt the availability of the affected interface. |
|
| CVE-2026-73743 | Sep 01, 2026 |
HPE Networking Fabric Composer: Unauth Remote Cleartext Data Exposure via Web UIA vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to gain insight into some data handled by the affected interface. A successful exploit could allow an attacker to gain access to some data in a cleartext format possibly exposing other network infrastructure to further compromise. |
|
| CVE-2026-73742 | Sep 01, 2026 |
HPE Networking Fabric Composer API Spoofing via Source Address AttributionA vulnerability in an API endpoint of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to spoof the source address attributed to their requests. Successful exploitation could allow an attacker to cause inaccurate attribution information to be recorded on the affected system. |
|
| CVE-2026-73741 | Sep 01, 2026 |
HPE Fabric Composer: Authenticated API Privilege Escalation via File DisclosureA vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to view some system files. Successful exploitation could allow an attacker to access limited data beyond what is authorized by the user's existing privilege level. |