TL;DR
HPE has patched two critical flaws in its server and network management tools. The first is an HPE iLO 7 vulnerability, CVE-2026-79820 (CVSS 9.0), which could give a remote attacker administrative access. The second, CVE-2026-79842 (CVSS 9.1), lets an attacker bypass authentication in HPE Intelligent Management Center (iMC).
- Product: Hewlett Packard Enterprise (HPE) HPE Integrated Lights-Out (iLO) 7, Hewlett Packard Enterprise HPE Intelligent Management Center (iMC)
- Vulnerabilities: 2 flaws (CVE-2026-79820, CVE-2026-79842)
- Highest severity: 9.1 (Critical · CVSSv3)
- Status: No confirmed exploitation yet; patches available
- Action: Update to 7.3 E0713 now
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-79842 | 9.1 | Awaiting analysis | 7.3 E0713 | Not exploited |
| CVE-2026-79820 | 9 | CWE-287 | — | Not exploited |
Route critical CVEs to one Slack channel, everything else to another.
Try Team free for 14 daysWhy It Matters
iLO is the out-of-band management controller built into HPE servers. It can power, configure and reinstall a server below the operating system. Meanwhile, iMC manages network devices across an organization. Control of either tool hands an attacker wide reach. HPE does not report any exploitation in the wild or a public proof-of-concept.
How the Attacks Work
iLO 7 User Validation Failure (CVE-2026-79820)
The flaw affects iLO 7 when used with HPE Compute Ops Management (COM). According to the iLO 7 security bulletin, it “could be remotely exploited to obtain administrative-level access to iLO.” The attack needs no login, though HPE rates its complexity as high. Its CVSS vector also marks the scope as changed, so the impact of this HPE iLO 7 vulnerability can reach beyond iLO itself. HPE found the bug internally.
iMC Authentication Bypass (CVE-2026-79842)
The iMC security bulletin says the iMC flaw “could [be] remotely exploited to allow authentication bypass.” It needs no credentials or user action. Researcher Nhi Nguyen reported the issue to HPE.
Affected Versions
- HPE iLO 7 version 1.25.00
- HPE iMC versions prior to v7.3 E0713
Only one iLO 7 release is listed, so the exposure window for that flaw is narrow. By contrast, every iMC build before the fix is affected.
Patch and Mitigation Steps
Update iLO 7 to version 1.25.01 or later through the HPE Support Center. Upgrade iMC to v7.3 E0713 from the HPE Aruba Support Portal. Until then, keep iLO and iMC interfaces on isolated management networks. That step limits exposure to this HPE iLO 7 vulnerability and the iMC bypass.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!