CriticalCritical vulnerability
CVE-2026-76724 (CVSS 9.6)
NVD · officialPublished Sep 29, 2026Risk 50/100
A command injection vulnerability exists in CLI of the affected HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to perform command injection by sending specially crafted packets. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
Technical details
CVSS
9.6
AV:Adjacent NetworkAC:LowPR:NoneUI:NoneC:HighI:HighA:High
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source