Hpe Hpe

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Hpe product.

RSS Feeds for Hpe security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Hpe products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Hpe Sorted by Most Security Vulnerabilities since 2018

Hpe Arubaos23 vulnerabilities

Hpe Insight Remote Support9 vulnerabilities

Hpe Autopass License Server8 vulnerabilities

Hpe Storeonce System8 vulnerabilities

Hpe Hpux Ntp4 vulnerabilities

Hpe 3par Service Provider2 vulnerabilities

Hpe Arubaos Cx1 vulnerability

By the Year

In 2026 there have been 174 vulnerabilities in Hpe with an average score of 7.0 out of ten. Last year, in 2025 Hpe had 60 security vulnerabilities published. That is, 114 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.07




Year Vulnerabilities Average Score
2026 174 7.03
2025 60 7.09
2024 7 8.81
2023 10 7.84
2022 11 7.44
2021 4 6.15
2020 3 6.90
2019 18 7.63
2018 234 0.00

It may take a day or so for new Hpe vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Hpe Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-73785 Sep 11, 2026
Remote Unauth DoS in HPE IceWall Federation Agent/Proxy A potential security vulnerability in HPE IceWall Federation Agent and Proxy could allow a remote unauthenticated attacker to cause a denial of service (DoS).
CVE-2026-73784 Sep 11, 2026
HPE IceWall SAML Response Tampering Allows User Impersonation A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML response, allowing an attacker to impersonate another user.
CVE-2026-73789 Sep 09, 2026
Unauthenticated Remote Exploit of HP CPPM Guest Account Web UI A vulnerability in the web-based management interface of CPPM guest account management services could allow an unauthenticated remote attacker to manipulate account settings. Successful exploitation could allow an attacker to extend network access beyond policy limits, leading to unauthorized prolonged use of network resources.
CVE-2026-73788 Sep 09, 2026
ClearPass OnGuard Agent PrivEsc Vulnerability A vulnerability in the ClearPass OnGuard agent could allow an authenticated remote attacker to elevate their own privileges on a vulnerable ClearPass OnGuard deployment. Successful exploitation could allow an attacker to obtain root privileges, leading to potentially unauthorized operation of the vulnerable system.
CVE-2026-73787 Sep 09, 2026
HPE CPPM RCE via Web Authenticated Directory Disclosure A vulnerability in the CPPM web interface could allow an authenticated remote attacker to access directory information on a vulnerable system. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
CVE-2026-73786 Sep 09, 2026
HPE CPPM Web UI DoS Vulnerability A vulnerability in the web-based management interface of CPPM could allow an unauthenticated remote attacker to conduct a Denial-of-Service (DoS) attack. Successful exploitation could allow an attacker to cause instability and degrade performance of the vulnerable CPPM server.
CVE-2026-73769 Sep 09, 2026
HPE CPPM RCE via Authenticated Web UI A vulnerability in the web-based management interface of vulnerable CPPM systems could allow an authenticated remote attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
CVE-2026-73783 Sep 01, 2026
AOS-CX API endpoint stack overflow leads to DOS Stack overflow vulnerabilities exist in an API endpoint of AOS-CX. Successful exploitation could allow an authenticated malicious actor to cause a denial-of-service condition on the affected system.
CVE-2026-73782 Sep 01, 2026
Format String Vulnerability in AOS-CX CLI Enables Unauth RCE A format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticated remote code execution. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.
CVE-2026-73781 Sep 01, 2026
HPE AOS-CX Authenticated Remote Stored XSS in Web UI A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
CVE-2026-73780 Sep 01, 2026
AOS-CX Web UI CSRF Enables Remote Execution A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Request Forgery (CSRF) protection. This could allow a remote unauthenticated attacker to execute arbitrary input against the affected interface if the attacker can convince an authenticated user of the interface to interact with a specially crafted URL.
CVE-2026-73779 Sep 01, 2026
Unauth Remote Bypass in HPE AOS-CX Switch OS Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could compromise system integrity and further expose sensitive information.
CVE-2026-73778 Sep 01, 2026
HPE Credential Manager: Factory-Default Password Allows Remote Admin Access A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthenticated remote attacker could exploit this vulnerability on a device in its factory-default or post-ZTP state before any administrator has configured credentials by providing a predictable factory-default password. Successful exploitation could result in full administrative control of the affected device during the initial setup process.
CVE-2026-73777 Sep 01, 2026
Unauthenticated API Auth Bypass in HPE AOS-CX Switches Vulnerabilities have been identified in the API endpoint of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls.
CVE-2026-73776 Sep 01, 2026
AOS-CX CLI Sig Verify Bypass RCE on OS A signature verification bypass vulnerability exists in the command line interface of AOS-CX. Successful exploitation could allow an authenticated malicious actor with administrative privileges to execute arbitrary code on the underlying operating system, when certain pre-conditions outside of the attackerâs control are met.
CVE-2026-73775 Sep 01, 2026
AOS-CX API Endpoint Info Disclosure via Low-privilege Auth Vulnerabilities in the API endpoint of AOS-CX could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by AOS-CX.
CVE-2026-73774 Sep 01, 2026
AOS-CX OS Buffer Overflow Enables Unauth Disclosure A buffer overflow vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated disclosure of sensitive information by sending specially crafted packets to the affected system. Successful exploitation of this vulnerability could result in limited disclosure or modification of information and disruption of the affected system.
CVE-2026-73773 Sep 01, 2026
AOS-CX API endpoint Unauthenticated DoS An unauthenticated Denial-of-Service (DoS) vulnerability exists in the API endpoint of AOS-CX. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected service.
CVE-2026-73772 Sep 01, 2026
AOS-CX Buffer Overflow in Service Enables Unauth DoS Buffer overflow vulnerabilities exist in an underlying service of AOS-CX that could lead to an unauthenticated denial-of-service condition by sending specially crafted packets to the affected device. Successful exploitation of these vulnerabilities results in a disruption of normal operation of the underlying operating system.
CVE-2026-73771 Sep 01, 2026
HPE AOS-CX Auth Bypass in Management Interface (CVE-2026-73771) An authentication vulnerability exists in the AOS-CX management interface and API that may allow improper authentication processing. An unauthenticated remote attacker could exploit this vulnerability under specific conditions to bypass authentication controls or exhaust system resources. Successful exploitation could result in unauthorized access or denial of service affecting the management interface.
CVE-2026-73770 Sep 01, 2026
Authenticated Arbitrary File Write in HPE Aruba AOS-CX OS An authenticated arbitrary file write vulnerability exists in AOS-CX. Successful exploitation could allow an authenticated malicious actor, under specific conditions outside the attacker's control and following a required action by another user, to create or modify arbitrary files and execute arbitrary commands as a privileged user on the underlying operating system.
CVE-2026-73768 Sep 01, 2026
Aruba AOS-CX CLI: Incorrect Input Processing Enables Root Exec A vulnerability exists in the command line interface of AOS-CX that may allow for improper processing of malformed input. Successful exploitation could result in the execution of arbitrary commands with root privileges.
CVE-2026-73767 Sep 01, 2026
AOS-CX CLI Authenticated Cmd Injection Enables Privileged OS Exec Authenticated command injection vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
CVE-2026-73766 Sep 01, 2026
AOS-CX API Command Injection Allowing Privileged OS Exec Command injection vulnerabilities in the API endpoint of AOS-CX could allow an authenticated remote attacker with administrative privileges to inject arbitrary commands. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
CVE-2026-73765 Sep 01, 2026
Path Traversal in AOS-CX API Enables Remote Code Exec Authenticated path traversal vulnerabilities exist in API endpoints of AOS-CX. Successful exploitation of these vulnerabilities allows an attacker to write arbitrary files to the underlying operating system, which could lead to remote code execution.
CVE-2026-73764 Sep 01, 2026
AOS-CX OS Auth Bypass via Unauthenticated Remote Actor Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable unauthorized modification of affected resources and limited disruption of affected services.
CVE-2026-73763 Sep 01, 2026
Unauth RCE in HPE iLO MGMT Component A vulnerability exists in a management component that could allow an unauthenticated adjacent attacker to execute arbitrary commands. Successful exploitation could result in remote execution of arbitrary commands in the context of the affected utility.
CVE-2026-73762 Sep 01, 2026
Remote Access Control Bypass via AOS-CX API Endpoint A vulnerability has been identified in the API endpoint of AOS-CX that could allow a remote actor to circumvent existing access controls. In some cases this could enable unauthorized access to management functionality that should be restricted by the configured access control policy.
CVE-2026-73761 Sep 01, 2026
AOS-CX OS OOB Read Leading to Info Disclosure via Packet An out-of-bounds read vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated information disclosure by sending a specially crafted packet. Successful exploitation of this vulnerability results in the ability to disclose sensitive information from the underlying operating system.
CVE-2026-73760 Sep 01, 2026
AOS-CX Path Traversal: Authenticated Access to OS Files An authenticated Path Traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to read arbitrary files from the web-based management interface of the underlying operating system, which could lead to remote unauthorized access to files.
CVE-2026-73759 Sep 01, 2026
AOS-CX DoS via Crafted Packets (Unauthenticated Remote) Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-of-service condition by sending specially crafted packets. Successful exploitation of these vulnerabilities results in disruption of normal operation on affected devices.
CVE-2026-73758 Sep 01, 2026
Privilege Escalation via API Endpoint in AOS-CX (HPE) A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulnerable system.
CVE-2026-73757 Sep 01, 2026
ArubaOS-CX SSRF via WebMgmt Interface A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a server-side request forgery (SSRF) attack. A successful exploit allows an attacker to enumerate information about the internal structure of the AOS-CX host, leading to potential disclosure and limited modification of sensitive information.
CVE-2026-73756 Sep 01, 2026
Remote API Endpoint Info Disclosure in HPE AOS-CX via MITM A vulnerability in an API endpoint of AOS-CX could allow a remote unauthenticated attacker to obtain sensitive information via a man-in-the-middle attack. Successful exploitation allows an attacker to retrieve data which could be used to further compromise the confidentiality of the affected system.
CVE-2026-73755 Sep 01, 2026
AOS-CX API Privilege Escalation via Authenticated Operator Access A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low-privilege operator user, after a required user action, to access sensitive information from the vulnerable system.
CVE-2026-73754 Sep 01, 2026
CVE-2026-73754: Authenticated DoS via AOS-CX CLI Denial-of-service vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation could allow an authenticated user to disrupt the normal operation of a vulnerable system.
CVE-2026-73753 Sep 01, 2026
HPE OneView CommandLine Privilege Escalation (CVE202673753) Exploitation through affected command-line operations could allow an authenticated low-privileged user to execute arbitrary commands as a privileged user on the underlying operating system.
CVE-2026-73752 Sep 01, 2026
AOS-CX API Arbitrary File Write Vulnerability An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. Successful exploitation of this vulnerability allows an attacker to write arbitrary files to the underlying operating system, which could lead to remote code execution.
CVE-2026-73751 Sep 01, 2026
Command Injection via Web UI in HPE iLO Low-Priv Auth An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system.
CVE-2026-73750 Sep 01, 2026
HPE Auth Module Improper Input Handling: DoS/Remote Code Exec Vulnerabilities exist in the authentication module that may improperly process malformed or truncated input. An authenticated remote attacker could exploit these vulnerabilities by providing specially crafted input from a compromised or hostile authentication server. Successful exploitation could result in a Denial-of-Service or potential remote code execution with elevated privileges.
CVE-2026-73749 Sep 01, 2026
ArubaOSCX Daemon Unauth RCE via Malformed Packets Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service. Successful exploitation could result in remote code execution with elevated privileges.
CVE-2026-76658 Sep 01, 2026
Unauth SSH Exploit in HPE Networking Fabric Composer SSH Daemon A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system leading to complete system compromise.
CVE-2026-76657 Sep 01, 2026
HPE Networking Fabric Composer un-auth RCE via API auth bypass Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the HPE Networking Fabric Composer host.
CVE-2026-73748 Sep 01, 2026
HPE Networking Fabric Composer Credentials Leak via Cleartext Interface A vulnerability in the affected interface of HPE Networking Fabric Composer allows an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking Fabric Composer.
CVE-2026-73747 Sep 01, 2026
Local Privilege Escalation in HPE Networking Fabric Composer A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user with local access to elevate their user privileges and make limited modifications on the affected system.
CVE-2026-73746 Sep 01, 2026
HPE Networking Fabric Composer API DoS Authenticated LowPrivilege Operator A denial-of-service vulnerability exists in the API of HPE Networking Fabric Composer that could allow an authenticated low privilege operator user to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service.
CVE-2026-73744 Sep 01, 2026
HPE Networking Fabric Composer Web UI DoS via Authenticated Low Privilege User A denial-of-service vulnerability exists in the web-based management interface of HPE Networking Fabric Composer that could allow an authenticated low privilege operator user to cause a denial of service. Successful exploitation could allow an attacker to disrupt the availability of the affected interface.
CVE-2026-73743 Sep 01, 2026
HPE Networking Fabric Composer: Unauth Remote Cleartext Data Exposure via Web UI A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to gain insight into some data handled by the affected interface. A successful exploit could allow an attacker to gain access to some data in a cleartext format possibly exposing other network infrastructure to further compromise.
CVE-2026-73742 Sep 01, 2026
HPE Networking Fabric Composer API Spoofing via Source Address Attribution A vulnerability in an API endpoint of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to spoof the source address attributed to their requests. Successful exploitation could allow an attacker to cause inaccurate attribution information to be recorded on the affected system.
CVE-2026-73741 Sep 01, 2026
HPE Fabric Composer: Authenticated API Privilege Escalation via File Disclosure A vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to view some system files. Successful exploitation could allow an attacker to access limited data beyond what is authorized by the user's existing privilege level.
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.