VulnSea

Hewlett Packard Enterprise (HPE) has 41 CVEs on record. Disclosure cadence is accelerating: 41 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 41. The median CVSS is 7.2 (high), with 3 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-120 (8) and CWE-400 (7). Most affected products: EdgeConnect SD-WAN Gateways (27), ALE (9), ClearPass Policy Manager (CPPM) (5).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.2
Publish → KEV
—
Last 90 days
41 prev 0

Products

  • EdgeConnect SD-WAN Gateways 27
  • ALE 9
  • ClearPass Policy Manager (CPPM) 5
Follow Hewlett Packard Enterprise (HPE):RSS feedSave a search →Embed badge ↗
41
Total CVEs
3
Critical
0
CISA KEV
0
Exploited

Hewlett Packard Enterprise (HPE) vulnerabilities

CVEs affecting Hewlett Packard Enterprise (HPE), newest first. Open any entry for full detail, references, and exploit status.

41 CVEsRSS

CVE-2026-76701Medium· 5.9
1w ago

A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to access sensitive information

A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to access sensitive information. Successful exploitation could allow an attacker to retrieve information whi…

▾ SunlitHewlett Packard Enterprise (HPE) · EdgeConnect SD-WAN GatewaysEPSS 0.39%via NVD
CVE-2026-76699Medium· 6.4
1w ago

A buffer overflow vulnerability exists in a system service within the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated adjacent attacker to cause a denial-of-service

A buffer overflow vulnerability exists in a system service within the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated adjacent attacker to cause a denial-of-service. Successfu…

▾ SunlitHewlett Packard Enterprise (HPE) · EdgeConnect SD-WAN GatewaysEPSS 0.22%via NVD
CVE-2026-76700Medium· 5.9
1w ago

Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to cause a denial-of-service

Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to cause a denial-of-service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected …

▾ SunlitHewlett Packard Enterprise (HPE) · EdgeConnect SD-WAN GatewaysEPSS 0.46%via NVD
CVE-2026-76707Medium· 4.3
1w ago

A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to view some system memory contents

A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to view some system memory contents. Successful exploitation could allow an attacker to gain insight into internal services an…

▾ SunlitHewlett Packard Enterprise (HPE) · EdgeConnect SD-WAN GatewaysEPSS 0.23%via NVD
CVE-2026-76703Medium· 5.5
1w ago

A buffer overflow vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways that could allow an authenticated attacker with administrative access to cause a denial of service

A buffer overflow vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways that could allow an authenticated attacker with administrative access to cause a denial of service. Successful exp…

▾ SunlitHewlett Packard Enterprise (HPE) · EdgeConnect SD-WAN GatewaysEPSS 0.38%via NVD
CVE-2026-76702Medium· 5.8
1w ago

A vulnerability in the operating system of HPE Networking EdgeConnect SD-WAN Gateways could allow an authenticated local attacker to cause a denial-of-service

A vulnerability in the operating system of HPE Networking EdgeConnect SD-WAN Gateways could allow an authenticated local attacker to cause a denial-of-service. Successful exploitation could allow an attacker to disrupt system operations,…

▾ SunlitHewlett Packard Enterprise (HPE) · EdgeConnect SD-WAN GatewaysEPSS 0.11%via NVD
CVE-2026-73787High· 7.2
2w ago

Authenticated Arbitrary File Write allows Remote Code Execution via CPPM Web Interface

A vulnerability in the CPPM web interface could allow an authenticated remote attacker to access directory information on a vulnerable system. Successful exploitation could allow an attacker to execute arbitrary commands on the underlyin…

▾ TwilightHewlett Packard Enterprise (HPE) · ClearPass Policy Manager (CPPM)EPSS 0.84%via CVEORG
CVE-2026-73769High· 7.2
2w ago

Authenticated Remote Code Execution in CPPM Web Interface

A vulnerability in the web-based management interface of vulnerable CPPM systems could allow an authenticated remote attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands…

▾ TwilightHewlett Packard Enterprise (HPE) · ClearPass Policy Manager (CPPM)EPSS 1.1%via CVEORG
CVE-2026-73789Medium· 5.3
2w ago

A vulnerability in the web-based management interface of CPPM guest account management services could allow an unauthenticated remote attacker to manipulate account settings

A vulnerability in the web-based management interface of CPPM guest account management services could allow an unauthenticated remote attacker to manipulate account settings. Successful exploitation could allow an attacker to extend netw…

▾ SunlitHewlett Packard Enterprise (HPE) · ClearPass Policy Manager (CPPM)EPSS 0.40%via NVD
CVE-2026-73788Medium· 6.5
2w ago

A vulnerability in the ClearPass OnGuard agent could allow an authenticated remote attacker to elevate their own privileges on a vulnerable ClearPass OnGuard deployment

A vulnerability in the ClearPass OnGuard agent could allow an authenticated remote attacker to elevate their own privileges on a vulnerable ClearPass OnGuard deployment. Successful exploitation could allow an attacker to obtain root priv…

▾ SunlitHewlett Packard Enterprise (HPE) · ClearPass Policy Manager (CPPM)EPSS 0.36%via NVD
CVE-2026-73786High· 7.5PoC
2w ago

A vulnerability in the web-based management interface of CPPM could allow an unauthenticated remote attacker to conduct a Denial-of-Service (DoS) attack

A vulnerability in the web-based management interface of CPPM could allow an unauthenticated remote attacker to conduct a Denial-of-Service (DoS) attack. Successful exploitation could allow an attacker to cause instability and degrade pe…

▾ MidnightHewlett Packard Enterprise (HPE) · ClearPass Policy Manager (CPPM)EPSS 0.57%via NVD
Hewlett Packard Enterprise (HPE) vulnerabilities (CVEs) — page 2 · VulnSea