OFFLINE
Awaiting data
Security intelligence
CriticalCritical vulnerability

CVE-2026-76724 (CVSS 9.6)

NVD · officialPublished Sep 29, 2026Risk 50/100

A command injection vulnerability exists in CLI of the affected HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to perform command injection by sending specially crafted packets. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.

CVSS
9.6
AV:Adjacent NetworkAC:LowPR:NoneUI:NoneC:HighI:HighA:High

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source