Hpe
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Hpe product.
RSS Feeds for Hpe security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Hpe products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Hpe Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 243 vulnerabilities in Hpe with an average score of 7.1 out of ten. Last year, in 2025 Hpe had 60 security vulnerabilities published. That is, 183 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.01
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 243 | 7.08 |
| 2025 | 60 | 7.09 |
| 2024 | 7 | 8.81 |
| 2023 | 10 | 7.84 |
| 2022 | 11 | 7.44 |
| 2021 | 4 | 6.15 |
| 2020 | 3 | 6.90 |
| 2019 | 18 | 7.63 |
| 2018 | 234 | 0.00 |
It may take a day or so for new Hpe vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Hpe Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-76738 | Sep 29, 2026 |
HPE Networking Instant On API Buffer Overflow (CVE-2026-76738)A buffer overflow vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service, which recovers without manual intervention. |
|
| CVE-2026-76737 | Sep 29, 2026 |
HPE Networking Instant On: Authenticated Path Traversal in CLIAn authenticated path traversal vulnerability exists in the command line interface of HPE Networking Instant On. Successful exploitation could allow an attacker with administrative access to modify a limited set of files on the underlying operating system and to interrupt the normal operation of the affected service. |
|
| CVE-2026-76736 | Sep 29, 2026 |
Buffer Overflow in HPE Networking Instant On OS Enables Local Auth AttackerA buffer overflow vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow a low-privilege authenticated local attacker to interrupt the normal operation of the affected service. |
|
| CVE-2026-76735 | Sep 29, 2026 |
CVE-2026-76735: Info Disclosure in HPE Networking Instant On OSA sensitive information disclosure vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow an authenticated local attacker with high privileges to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking Instant On, only if certain preconditions outside of the attacker's control are met. |
|
| CVE-2026-76734 | Sep 29, 2026 |
Memory Corruption in HPE Instant On Intf Enables Remote DoSA memory corruption vulnerability in the affected interface of HPE Networking Instant On could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service and to access some limited information within the affected component. |
|
| CVE-2026-76733 | Sep 29, 2026 |
HPE Networking Instant On API Authenticated DoSA denial-of-service vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service, which resumes without manual intervention. |
|
| CVE-2026-76732 | Sep 29, 2026 |
Local Privilege Escalation in HPE Networking Instant ON DaemonA local privilege-escalation vulnerability has been discovered in the affected daemon of HPE Networking Instant ON. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges if certain preconditions are met outside of the attacker's control. |
|
| CVE-2026-76731 | Sep 29, 2026 |
CVE-2026-76731: Auth Bypass in HPE Networking Instant On Captive PortalAn authentication bypass vulnerability in the captive portal of HPE Networking Instant On could allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain limited access to some data and to make limited changes within the affected component. |
|
| CVE-2026-76730 | Sep 29, 2026 |
HPE Instant ON AP Authentication Bypass via PAPI ProtocolAn authentication bypass vulnerability exists in the PAPI protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to circumvent certain existing authentication mechanisms and send unauthorized network traffic to the target device. |
|
| CVE-2026-76729 | Sep 29, 2026 |
HPE Instant ON AP Format String Vulnerability (CVE-2026-76729)A format string vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to cause memory corruption with a modified input. Successful exploitation could allow an attacker to provoke a denial-of-service condition or remote code execution in the affected system function. |
|
| CVE-2026-76728 | Sep 29, 2026 |
SSRF in HPE Networking Instant ON AP API allows privileged command execA vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to conduct a server-side request forgery (SSRF) attack. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system. |
|
| CVE-2026-76727 | Sep 29, 2026 |
HPE Networking Instant ON Command Injection via Authenticated Remote InterfaceCommand injection vulnerabilities exist in the affected interface of HPE Networking Instant ON that could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system. |
|
| CVE-2026-76726 | Sep 29, 2026 |
Auth Bypass in HPE Networking Instant ON API endpointAn authentication bypass vulnerability in the API endpoint of HPE Networking Instant ON could allow an unauthenticated remote attacker to bypass network access controls if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to obtain unauthorized access to restricted networks. |
|
| CVE-2026-76725 | Sep 29, 2026 |
HPE Instant ON AP Auth Bypass via Management Protocol (CVE-2026-76725)A vulnerability has been identified in a management protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication controls. Successful exploitation could result in a complete bypass of security restrictions, potentially leading to remote code execution with elevated privileges. |
|
| CVE-2026-76724 | Sep 29, 2026 |
Command Injection in HPE Instant ON AP CLI allows Privileged OS Cmd ExecA command injection vulnerability exists in CLI of the affected HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to perform command injection by sending specially crafted packets. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system. |
|
| CVE-2026-76723 | Sep 29, 2026 |
Buffer Overflow in HPE Instant ON APS Interface Causing RCEBuffer overflow vulnerabilities exist in the affected interface of HPE Networking Instant ON APS that could allow an unauthenticated adjacent attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. |
|
| CVE-2026-76722 | Sep 29, 2026 |
HPE Instant ON AP: Uncontrolled Format String Vulnerability Enabling RCEUncontrolled Format string vulnerabilities exist in the affected interface of HPE Networking Instant ON APs that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation could result in a Denial-of-service or potential remote code execution. |
|
| CVE-2026-76721 | Sep 29, 2026 |
Buffer Overflow in HPE Networking Instant ON Enables RCEBuffer overflow vulnerability exists in the affected interface of HPE Networking Instant ON that could allow an unauthenticated remote attacker to run arbitrary code on the underlying host. Successful exploitation could allow an attacker to execute arbitrary code as a privileged user on the underlying operating system. |
|
| CVE-2026-76720 | Sep 29, 2026 |
HPE OneView URL Redirect (Remote Exploit)A vulnerability in HPE OneView can be remotely exploited to cause a URL redirect. |
|
| CVE-2026-76719 | Sep 29, 2026 |
Session Hijacking Vulnerability in HPE OneViewA security vulnerability in HPE OneView may be exploited remotely to perform session hijacking, data theft or other unauthorized actions. |
|
| CVE-2026-76718 | Sep 29, 2026 |
HPE OneView Remote Session Hijacking VulnerabilityA potential security vulnerability in HPE OneView can be exploited to allow remote session hijacking or other unauthorized actions. |
|
| CVE-2026-76717 | Sep 22, 2026 |
ALE API Info Disclosure in HPE Analytics & Location EngineA vulnerability exists in the Analytics and Location Engine (ALE) API that may allow for the disclosure of sensitive information. An unauthenticated remote attacker could exploit this vulnerability by providing specially crafted input to a specific API endpoint. Successful exploitation could result in the disclosure of sensitive user information, including password hashes, which could be used to facilitate further attacks. |
|
| CVE-2026-76716 | Sep 22, 2026 |
Unauth Remote DoS & Escalation in HPE Aruba ALEMultiple vulnerabilities exist in the Analytics and Location Engine (ALE) that may allow for unauthorized access or denial of service. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted input or leveraging improper security configurations. Successful exploitation could result in a denial of service condition or unauthorized access to sensitive information. |
|
| CVE-2026-76715 | Sep 22, 2026 |
HPE ALE MitM allows root code execA vulnerability in an administrative component of Analytics and Location Engine (ALE) is vulnerable to a man-in-the-middle (MitM) attack. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on the affected appliance. |
|
| CVE-2026-76714 | Sep 22, 2026 |
HPE Analytics & Loc Engine RCE via Web InterfaceVulnerabilities in the Analytics and Location Engine web interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise. |
|
| CVE-2026-76713 | Sep 22, 2026 |
HPE ALE File System Privileges Escalation via Maintenance RestoreA vulnerability exists in the maintenance restore functionality of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an authenticated remote attacker to gain unauthorized access to the file system with root privileges, potentially resulting in full system compromise. |
|
| CVE-2026-76712 | Sep 22, 2026 |
Unauthorized Access & DoS in HPE ALE (Analytics & Location Engine)A vulnerability exists in the Analytics and Location Engine (ALE) that may allow for unauthorized access, information disclosure, or denial of service. An unauthenticated remote attacker could exploit the vulnerable system by sending specially crafted input or intercepting network communications. Successful exploitation could result in the disclosure of sensitive information, bypass of security controls, or a denial of service condition on the affected system. |
|
| CVE-2026-76710 | Sep 22, 2026 |
HPE ALE: Remote Unauth Info Disclosure via Internal EndpointsA vulnerability exists in the Analytics and Location Engine (ALE) management interface that may allow for the disclosure of sensitive information. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted requests to certain internal endpoints. Successful exploitation could result in the disclosure of sensitive site hierarchy, infrastructure details, and client device information. |
|
| CVE-2026-76711 | Sep 22, 2026 |
HPE ALE Socket Input Injection VulnerabilityA vulnerability exists in an Analytics and Location Engine (ALE) component where the impacted process improperly processes incoming socket connections. An unauthenticated remote attacker could exploit this vulnerability by providing specially crafted input during the connection process. Successful exploitation could result in unauthorized data injection. |
|
| CVE-2026-76709 | Sep 22, 2026 |
HPE ALE Admin Component Remote Write Privilege EscalationA vulnerability exists in the internal administrative component of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to gain unauthorized write access to the file system with elevated privileges, potentially resulting in full system compromise. |
|
| CVE-2026-76708 | Sep 22, 2026 |
Hardcoded Default Credentials in HPE ALE Enable Remote AccessA vulnerability exists in the Analytics and Location Engine (ALE) where the application and underlying operating system use default, hard-coded credentials for several administrative and system accounts. An unauthenticated remote attacker could exploit this vulnerability by attempting to log in using these known default credentials. Successful exploitation could result in an attacker gaining unauthorized access to the application's management interface and the underlying operating system, potentially leading to full system compromise. |
|
| CVE-2026-76706 | Sep 15, 2026 |
Unauthenticated API Disclosure in HPE EdgeConnect SD-WAN OrchestratorA vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to obtain sensitive information. Successful exploitation could result in the disclosure of security-relevant configuration details and security feature status, which could be used to facilitate further attacks. |
|
| CVE-2026-76707 | Sep 15, 2026 |
HPE EdgeConnect SD-WAN Gateway Memory Disclosure via Adjacent AttackA vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to view some system memory contents. Successful exploitation could allow an attacker to gain insight into internal services and workflows, increasing the risk of unauthorized access and elevated privileges when combined with other vulnerabilities. |
|
| CVE-2026-76705 | Sep 15, 2026 |
HPE EdgeConnect SD-WAN Gateway API Buffer Overflow CVE-2026-76705A buffer overflow vulnerability exists in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with Admin privilege to execute arbitrary commands on the underlying operating system. |
|
| CVE-2026-76704 | Sep 15, 2026 |
EdgeConnect Orchestrator XSS: Auth Exec Arbitrary Script CodeA vulnerability in the web-based management interface of the EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to execute arbitrary script code in a victim's browser in the context of the affected interface. Successful exploitation could allow an attacker to access sensitive information, potentially affecting the confidentiality and integrity of the data processed by the application. |
|
| CVE-2026-76703 | Sep 15, 2026 |
Buffer Overflow in HPE EdgeConnect SD-WAN Gateway Web UI DoSA buffer overflow vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways that could allow an authenticated attacker with administrative access to cause a denial of service. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an unstable system state. |
|
| CVE-2026-76702 | Sep 15, 2026 |
A vulnerability in the operating system of HPE Networking EdgeConnect SD-WAN Gateways couldA vulnerability in the operating system of HPE Networking EdgeConnect SD-WAN Gateways could allow an authenticated local attacker to cause a denial-of-service. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an unstable system state. |
|
| CVE-2026-76700 | Sep 15, 2026 |
Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to cause a denial-of-serviceVulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to cause a denial-of-service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service. |
|
| CVE-2026-76701 | Sep 15, 2026 |
A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways couldA vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to access sensitive information. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking EdgeConnect SD-WAN Gateways. |
|
| CVE-2026-76699 | Sep 15, 2026 |
A buffer overflow vulnerability exists in a system service within the underlying operating system of HPE Networking EdgeConnect SD-WAN GatewaysA buffer overflow vulnerability exists in a system service within the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated adjacent attacker to cause a denial-of-service. Successful exploitation could allow an attacker to crash the impacted service and temporarily disrupting network operations. |
|
| CVE-2026-76698 | Sep 15, 2026 |
A command injection vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN GatewaysA command injection vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways. An authenticated remote attacker with limited access privileges could exploit this vulnerability through specially crafted input. Successful exploitation, under certain conditions, could result in the execution of arbitrary commands with elevated privileges or a denial-of-service condition on the affected appliance. |
|
| CVE-2026-76697 | Sep 15, 2026 |
A vulnerability in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways couldA vulnerability in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking EdgeConnect SD-WAN Gateways. |
|
| CVE-2026-76696 | Sep 15, 2026 |
A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways couldA vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to crash the system, preventing it from rebooting without manual intervention and disrupting network operations. |
|
| CVE-2026-76695 | Sep 15, 2026 |
Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN GatewaysBuffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to send specially crafted packets to the affected service. Successful exploitation could allow an attacker to affect the integrity and availability of the affected service. |
|
| CVE-2026-76694 | Sep 15, 2026 |
A privilege escalation vulnerability exists in the command line interface of HPE Networking EdgeConnect SD-WAN GatewaysA privilege escalation vulnerability exists in the command line interface of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with high privileges to escalate privileges beyond their authorized level, and execute arbitrary code on a vulnerable system. |
|
| CVE-2026-76693 | Sep 15, 2026 |
A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways couldA vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to cause a denial-of-service against certain services running on impacted Gateways. |
|
| CVE-2026-76692 | Sep 15, 2026 |
A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways couldA vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to obtain limited information from memory and disrupt the normal operation of the affected service. Successful exploitation could result in a denial of service (system crash) or the disclosure of uninitialized stack memory. |
|
| CVE-2026-76691 | Sep 15, 2026 |
Buffer overflow vulnerabilities exist in the API endpoint of HPE Networking EdgeConnect SD-WAN GatewaysBuffer overflow vulnerabilities exist in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker to execute arbitrary commands as a privileged user on the underlying operating system. |
|
| CVE-2026-76690 | Sep 15, 2026 |
A vulnerability exists in a component of the HPE Networking EdgeConnect SD-WAN Gateways that may allow for arbitrary command executionA vulnerability exists in a component of the HPE Networking EdgeConnect SD-WAN Gateways that may allow for arbitrary command execution. An authenticated remote attacker could exploit this vulnerability by providing a specially crafted input to the affected component. Successful exploitation could result in remote code execution as root. |
|
| CVE-2026-76688 | Sep 15, 2026 |
Vulnerabilities have been identified in the web-based management interface of EdgeConnect SD-WAN OrchestratorVulnerabilities have been identified in the web-based management interface of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the EdgeConnect SD-WAN Orchestrator host. |