TL;DR
HPE Networking disclosed 18 HPE Instant ON vulnerabilities on September 29, 2026, in its Instant ON access points. Five are rated Critical, and the two worst score CVSS 9.8 with unauthenticated remote code execution. Instant ON 3.4.2.0 fixes all of them.
- Total: 18 CVEs
- Severity: 5 Critical · 3 High · 7 Medium · 3 Low
- Actively exploited: None confirmed
- Highest severity: 9.8 (Critical · CVSSv3) — CVE-2026-76721
- Action: Apply the latest security updates now
Route critical CVEs to one Slack channel, everything else to another.
Try Team free for 14 daysNotable CVEs
| CVE | CVSS (CVSSv3) | Type | Status |
|---|---|---|---|
| CVE-2026-76721 | 9.8 | Unauthenticated Buffer Overflow leads to Remote Code Execution in HPE Networking APs | Not exploited |
| CVE-2026-76722 | 9.8 | Uncontrolled Format String lead to Remote Code Execution or Denial-of-Service in HPE Networking APs | Not exploited |
| CVE-2026-76723 | 9.6 | Unauthenticated Adjacent Buffer Overflow lead to Remote Code Execution in HPE Networking APS | Not exploited |
| CVE-2026-76724 | 9.6 | Unauthenticated Adjacent Command Injection in HPE Networking APs Command Line Interface (CLI) Accessed by the PAPI Protocol | Not exploited |
| CVE-2026-76725 | 9.6 | Authentication Bypass in a Management Protocol of HPE Networking APs | Not exploited |
| CVE-2026-76726 | 8.1 | Authentication Bypass Leading to Unauthorized Network Access in HPE Networking API Endpoint | Not exploited |
| CVE-2026-76727 | 7.2 | Authenticated Command Injection in HPE Networking | Not exploited |
| CVE-2026-76728 | 7.2 | Authenticated Server-Side Request Forgery Leading to Remote Code Execution in HPE Networking APs | Not exploited |
Why These HPE Instant ON Vulnerabilities Matter
Instant ON is HPE’s cloud-managed Wi-Fi line for small businesses. These offices often lack a dedicated security team. An access point also sits inside the network, so a takeover gives an attacker a strong foothold.
The batch includes five Critical, three High, seven Medium, and three Low issues. Several need no login at all. HPE’s own researchers found every flaw.
How the Attacks Work
Remote Code Execution Without Authentication
CVE-2026-76721 is a buffer overflow in an exposed interface. According to the HPE Instant ON security advisory, it “could allow an unauthenticated remote attacker to run arbitrary code on the underlying host.” CVE-2026-76722 covers format string bugs that can lead to code execution or a crash.
Adjacent Network Attacks
Three more Critical flaws score CVSS 9.6. They require an attacker on the same local network segment. CVE-2026-76723 groups several buffer overflows. CVE-2026-76724 is a command injection in the CLI, reachable through the PAPI management protocol. Meanwhile, CVE-2026-76725 is an authentication bypass in a management protocol that could lead to code execution.
Other Flaws
The rest include an API authentication bypass (CVSS 8.1), a captive portal bypass, and admin-level command injection and SSRF bugs. Local privilege escalation, information disclosure, and denial-of-service issues round out the list.
Affected Versions and Exploitation Status
The flaws affect Instant ON 3.4.1.0 and below. HPE warns that versions past End of Maintenance are presumed affected. HPE says it “is not aware of any public discussion or exploit code that targets the listed vulnerabilities.” No exploitation in the wild has been confirmed.
Patch and Mitigation Steps
Upgrade to Instant ON 3.4.2.0 or later. The Instant ON cloud portal applies the fix to access points automatically, but admins should confirm each device updated. Check the firmware version for every site in the portal. Until then, HPE advises limiting web-based management interfaces to a dedicated layer 2 segment or VLAN, or to firewall policies. Given the number of HPE Instant ON vulnerabilities with no login required, HPE urges customers to patch quickly.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!