---
id: CVE-2026-76721
title: >-
  Buffer overflow vulnerability exists in the affected interface of HPE
  Networking Instant ON that could allow an unauthenticated remote attacker to
  run arbitrary code on the underlying host
summary: >-
  Buffer overflow vulnerability exists in the affected interface of HPE
  Networking Instant ON that could allow an unauthenticated remote attacker to
  run arbitrary code on the underlying host. Successful exploitation could allow
  an attacker…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
vendor: Hewlett Packard Enterprise (HPE)
product: Instant ON
affected:
  - instant_on >= 0.0.0.0 <= 3.4.1.0
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T21:39:02.570'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76721'
references:
  - url: >-
      https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US
    label: security-alert@hpe.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T19:44:04.158Z'
---

## Overview

Buffer overflow vulnerability exists in the affected interface of HPE Networking Instant ON that could allow an unauthenticated remote attacker to run arbitrary code on the underlying host. Successful exploitation could allow an attacker to execute arbitrary code as a privileged user on the underlying operating system.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
