CVE-2026-76728: high-severity vulnerability in Hewlett Packard Enterprise (HPE) Instant ON
Authenticated Server-Side Request Forgery Leading to Remote Code Execution in HPE Networking Instant ON APs
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.2epss 0.5%
exploitation probability
0.5%top 59% of all CVEs
observed exploitation
nono source reports it
A vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to conduct a server-side request forgery (SSRF) attack. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
Hewlett Packard Enterprise (HPE) · Instant ONRelated CVEs — Hewlett Packard Enterprise (HPE) Instant ON
In the same product, most dangerous first.
CVE-2026-76724CRITICALUnauthenticated Adjacent Command Injection Vulnerability in HPE Networking Instant ON APs Command Line Interface (CLI) Accessed by the PAPI ProtocolEPSS 1.0%CVE-2026-76727HIGHAuthenticated Command Injection Vulnerabilities in HPE Networking Instant ONEPSS 1.0%CVE-2026-76721CRITICALUnauthenticated Buffer Overflow Vulnerability leads to Remote Code Execution in HPE Networking Instant ON APsEPSS 0.6%CVE-2026-76722CRITICALUncontrolled Format String Vulnerabilities lead to Remote Code Execution or Denial-of-Service in HPE Networking Instant ON APsEPSS 0.5%CVE-2026-76729MEDIUMAuthenticated Format String Vulnerability allows Memory Corruption in HPE Networking Instant ON API EndpointEPSS 0.4%CVE-2026-76726HIGHAuthentication Bypass Leading to Unauthorized Network Access in HPE Networking Instant ON API EndpointEPSS 0.4%