CVE-2025-37107: HPE Autopass License Server

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.

Affected products

  • HPE Autopass License Server: before 9.18 (fixed in 9.18)

Published 2025-07-16. Last modified 2026-06-17.