CVE-2026-76725: Hewlett Packard Enterprise HPE Instant On

Critical severity, CVSS 9.6. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability has been identified in a management protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication controls. Successful exploitation could result in a complete bypass of security restrictions, potentially leading to remote code execution with elevated privileges.

Affected products

Published 2026-09-29. Last modified 2026-10-01.