CVE-2026-79820Critical· 9.0▾ MidnightA remote user validation failure vulnerability exists in HPE Integrated Lights-Out (iLO) 7 firmware.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 49.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
A remote user validation failure vulnerability exists in HPE Integrated Lights-Out (iLO) 7 firmware.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-76725Critical· 9.6A vulnerability has been identified in a management protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication controls
CVE-2026-76726High· 8.1An authentication bypass vulnerability in the API endpoint of HPE Networking Instant ON could allow an unauthenticated remote attacker to bypass network access controls if certain preconditions outside of the attacker's control are met
CVE-2026-76730Medium· 6.5An authentication bypass vulnerability exists in the PAPI protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication controls
CVE-2026-76736Low· 3.3A buffer overflow vulnerability exists in the underlying operating system of HPE Networking Instant On
CVE-2026-76721Critical· 9.8Buffer overflow vulnerability exists in the affected interface of HPE Networking Instant ON that could allow an unauthenticated remote attacker to run arbitrary code on the underlying host
CVE-2026-76723Critical· 9.6Buffer overflow vulnerabilities exist in the affected interface of HPE Networking Instant ON APS that could allow an unauthenticated adjacent attacker to achieve remote code execution