CVE-2026-73789Unauthenticated Insecure Parameter Manipulation allows Data Tampering In CPPM Web Interface Exploitation status Not known exploited Fix Not confirmed Affected product C ClearPass Policy Manager (CPPM) Published 09/09/2026 Severity Medium CVE-2026-73788Privilege Escalation in ClearPass OnGuard Agent Exploitation status Not known exploited Fix Not confirmed Affected product C ClearPass Policy Manager (CPPM) Published 09/09/2026 Severity Medium CVE-2026-73787Authenticated Arbitrary File Write allows Remote Code Execution via CPPM Web Interface Exploitation status Not known exploited Fix Not confirmed Affected product C ClearPass Policy Manager (CPPM) Published 09/09/2026 Severity High CVE-2026-73786Unauthenticated Network-Based Denial of Service in CPPM systems Exploitation status Not known exploited Fix Not confirmed Affected product C ClearPass Policy Manager (CPPM) Published 09/09/2026 Severity High CVE-2026-73769Authenticated Remote Code Execution in CPPM Web Interface Exploitation status Not known exploited Fix Not confirmed Affected product C ClearPass Policy Manager (CPPM) Published 09/09/2026 Severity High CVE-2026-73783Authenticated Stack Overflow Vulnerabilities lead to Denial-of-Service in AOS-CX Exploitation status Not known exploited Fix Not confirmed Affected product A AOS-CX Published 09/01/2026 Severity Medium CVE-2026-73782Unauthenticated Format String Vulnerability leads to Remote Code Execution in AOS-CX Exploitation status Not known exploited Fix Not confirmed Affected product A AOS-CX Published 09/01/2026 Severity High CVE-2026-73781Authenticated Stored Cross-Site Scripting Vulnerability (XSS) in AOS-CX Web-Based Management Interface Exploitation status Not known exploited Fix Not confirmed Affected product A AOS-CX Published 09/01/2026 Severity High CVE-2026-73780Lack of Cross-Site Request Forgery (CSRF) Protections for Certificate-Authenticated Sessions in AOS-CX Exploitation status Not known exploited Fix Not confirmed Affected product A AOS-CX Published 09/01/2026 Severity High CVE-2026-73779Authentication Bypass Vulnerabilities Leading to Information Disclosure, Unauthorized Modification, and Service Disruption in AOS-CX Exploitation status Not known exploited Fix Not confirmed Affected product A AOS-CX Published 09/01/2026 Severity High CVE-2026-73778Credential Manager Vulnerability Allows Unauthorized Administrative Access Exploitation status Not known exploited Fix Not confirmed Affected product A AOS-CX Published 09/01/2026 Severity High CVE-2026-73777Authorization Bypass Vulnerabilities Leading to Privilege Escalation in AOS-CX API Endpoint Exploitation status Not known exploited Fix Not confirmed Affected product A AOS-CX Published 09/01/2026 Severity High CVE-2026-73776Authenticated Signature Verification Bypass Leading to Arbitrary Code Execution in AOS-CX Exploitation status Not known exploited Fix Not confirmed Affected product A AOS-CX Published 09/01/2026 Severity High CVE-2026-73775Authenticated Sensitive Information Disclosure Vulnerabilities in AOS-CX Exploitation status Not known exploited Fix Not confirmed Affected product A AOS-CX Published 09/01/2026 Severity High CVE-2026-73774Unauthenticated Buffer Overflow Vulnerability leads to Sensitive Information Disclosure in AOS-CX Exploitation status Not known exploited Fix Not confirmed Affected product A AOS-CX Published 09/01/2026 Severity High CVE-2026-73773Unauthenticated Denial-of-Service (DoS) Vulnerability in AOS-CX Exploitation status Not known exploited Fix Not confirmed Affected product A AOS-CX Published 09/01/2026 Severity High CVE-2026-73772Unauthenticated Buffer Overflow Vulnerabilities lead to Denial-of-Service in AOS-CX Exploitation status Not known exploited Fix Not confirmed Affected product A AOS-CX Published 09/01/2026 Severity Medium CVE-2026-73771Improper Authentication Handling in AOS-CX Management Interface and API Exploitation status Not known exploited Fix Not confirmed Affected product A AOS-CX Published 09/01/2026 Severity High CVE-2026-73770Authenticated Arbitrary File Write Vulnerability Leading to Remote Code Execution in AOS-CX Exploitation status Not known exploited Fix Not confirmed Affected product A AOS-CX Published 09/01/2026 Severity High CVE-2026-73768Local Privilege Escalation in AOS-CX Command Line Interface Exploitation status Not known exploited Fix Not confirmed Affected product A AOS-CX Published 09/01/2026 Severity High CVE-2026-73767Authenticated Remote Command Injection Vulnerabilities in AOS-CX Command Line Interface Exploitation status Not known exploited Fix Not confirmed Affected product A AOS-CX Published 09/01/2026 Severity High CVE-2026-73766Authenticated Command Injection Vulnerabilities in the API Endpoint of AOS-CX Exploitation status Not known exploited Fix Not confirmed Affected product A AOS-CX Published 09/01/2026 Severity High CVE-2026-73765Authenticated Path Traversal Vulnerabilities Lead to Remote Code Execution in AOS-CX Exploitation status Not known exploited Fix Not confirmed Affected product A AOS-CX Published 09/01/2026 Severity High CVE-2026-73764Authentication Bypass Vulnerabilities Leading to Unauthorized Modification and Service Disruption in AOS-CX Exploitation status Not known exploited Fix Not confirmed Affected product A AOS-CX Published 09/01/2026 Severity High CVE-2026-73763Unauthenticated Remote Command Execution in Management Component Exploitation status Not known exploited Fix Not confirmed Affected product A AOS-CX Published 09/01/2026 Severity High CVE-2026-73762Authorization Bypass in the API Endpoint of AOS-CX Leads to Unauthorized Access Exploitation status Not known exploited Fix Not confirmed Affected product A AOS-CX Published 09/01/2026 Severity Medium CVE-2026-73761Unauthenticated Out-of-Bounds Read Vulnerability leads to Information Disclosure in AOS-CX Exploitation status Not known exploited Fix Not confirmed Affected product A AOS-CX Published 09/01/2026 Severity Medium CVE-2026-73760Authenticated Path Traversal Vulnerability Leads to Remote Unauthorized Access to Files in AOS-CX Exploitation status Not known exploited Fix Not confirmed Affected product A AOS-CX Published 09/01/2026 Severity Medium CVE-2026-73759Unauthenticated Denial-of-Service Vulnerabilities in AOS-CX Exploitation status Not known exploited Fix Not confirmed Affected product A AOS-CX Published 09/01/2026 Severity Medium CVE-2026-73758Authenticated Privilege Escalation Vulnerability via Broken Access Control in AOS-CX Exploitation status Not known exploited Fix Not confirmed Affected product A AOS-CX Published 09/01/2026 Severity Medium CVE-2026-73757Authenticated Server-Side Request Forgery (SSRF) Leading to Information Disclosure in AOS-CX Exploitation status Not known exploited Fix Not confirmed Affected product A AOS-CX Published 09/01/2026 Severity Medium CVE-2026-73756Unauthenticated Sensitive Information Disclosure via Man-in-the-Middle in AOS-CX via API Endpoint Exploitation status Not known exploited Fix Not confirmed Affected product A AOS-CX Published 09/01/2026 Severity Medium CVE-2026-73755Privilege Escalation via Unauthorized Access to Sensitive Session Information Exploitation status Not known exploited Fix Not confirmed Affected product A AOS-CX Published 09/01/2026 Severity Medium CVE-2026-73754Authenticated Denial-of-Service Vulnerabilities in the Command Line Interface of AOS-CX Exploitation status Not known exploited Fix Not confirmed Affected product A AOS-CX Published 09/01/2026 Severity Medium CVE-2026-73753Authenticated Remote Command Injection Vulnerabilities in AOS-CX Command Line Interface Exploitation status Not known exploited Fix Not confirmed Affected product A AOS-CX Published 09/01/2026 Severity High CVE-2026-73752Unauthenticated Arbitrary File Write Vulnerability Leads to Remote Code Execution in AOS-CX Exploitation status Not known exploited Fix Not confirmed Affected product A AOS-CX Published 09/01/2026 Severity High CVE-2026-73751Authenticated Remote Command Injection in AOS-CX Web-based Management Interface Exploitation status Not known exploited Fix Not confirmed Affected product A AOS-CX Published 09/01/2026 Severity High CVE-2026-73750Authenticated Buffer Overflow Vulnerabilities in AOS-CX API Endpoint Leads to Possible Code Execution Exploitation status Not known exploited Fix Not confirmed Affected product A AOS-CX Published 09/01/2026 Severity High CVE-2026-73749Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX Exploitation status Not known exploited Fix Not confirmed Affected product A AOS-CX Published 09/01/2026 Severity Critical CVE-2026-76658Unauthenticated Remote Code Execution in HPE Networking Fabric Composer SSH Daemon Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity Critical CVE-2026-76657Authentication Bypass in HPE Networking Fabric Composer API allows Administrative Access Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity Critical CVE-2026-73748Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity Low CVE-2026-73747Local Privilege Escalation Vulnerability in HPE Networking Fabric Composer Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity Low CVE-2026-73746Authenticated Denial of Service Vulnerability in HPE Networking Fabric Composer API Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity Low CVE-2026-73744Authenticated Denial of Service Vulnerability in HPE Networking Fabric Composer Web-Based Management Interface Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity Low CVE-2026-73743Unauthenticated Information Disclosure Leading to Data Exposure in HPE Networking Fabric Composer Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity Low CVE-2026-73742Improper Client Address Validation allows Request Attribution Spoofing in Fabric Composer API Endpoint Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity Medium CVE-2026-73741Authenticated Limited File Read allows Data Exposure in HPE Networking Fabric Composer API Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity Medium CVE-2026-73740Local Privilege Escalation in HPE Networking Fabric Composer Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity Medium CVE-2026-73739Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer API Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity Medium CVE-2026-73738Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity Medium CVE-2026-73737Unauthenticated Path Traversal in HPE Networking Fabric Composer API Endpoint Allows Unauthorized File Modification Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity Medium CVE-2026-73736Unauthenticated Limited Information Disclosure leads to Data Exposure in HPE Networking Fabric Composer Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity Medium CVE-2026-73735Authenticated Access Control Vulnerabilities allow Information Disclosure in HPE Networking Fabric Composer API Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity Medium CVE-2026-73734Unauthenticated Open Redirect allows URL Manipulation in HPE Networking Fabric Composer Web Interface Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity Medium CVE-2026-73733Authentication Bypasses in API allow Continued Authenticated Access in HPE Networking Fabric Composer Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity Medium CVE-2026-73732Local Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity Medium CVE-2026-73731Unauthenticated Reflected Cross-Site Scripting (XSS) Vulnerability in HPE Networking Fabric Composer Web-Based Management Interface Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity Medium CVE-2026-73730Authenticated Privilege Escalation via Broken Access Control in HPE Networking Fabric Composer API Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity Medium CVE-2026-73729Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity Medium CVE-2026-73728Authenticated Denial of Service Vulnerabilities in HPE Networking Fabric Composer API Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity Medium CVE-2026-73727Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer API Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity Medium CVE-2026-73726Authentication Bypass in HPE Networking Fabric Composer allows Unauthorized Administrative Access Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity Medium CVE-2026-73725Local Privilege Escalation leads to Arbitrary Code Execution in HPE Networking Fabric Composer Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity High CVE-2026-73724Authenticated Privilege Escalation via Broken Access Control in HPE Networking Fabric Composer Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity High CVE-2026-73723Authenticated Privilege Escalation Leading to Unauthorized State Changes in HPE Networking Fabric Composer Web-Based Management Interface Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity High CVE-2026-73722Authenticated Command Injection Vulnerabilities in HPE Networking Fabric Composer Web-Based Management Interface Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity High CVE-2026-73721Authenticated SQL Injection Vulnerabilities in HPE Networking Fabric Composer Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity High CVE-2026-73720Authenticated Insecure File Handling allows Remote Code Execution in HPE Networking Fabric Composer API Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity High CVE-2026-73719Authenticated Arbitrary File Write Vulnerability leads to Remote Code Execution in HPE Networking Fabric Composer Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity High CVE-2026-73718Unauthenticated Information Disclosure in Web Interface allows Sensitive Data Exposure in HPE Networking Fabric Composer Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity High CVE-2026-73717Unauthenticated Command Injection Vulnerability in HPE Networking Fabric Composer Web-Based Management Interface Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity High CVE-2026-73716Unauthenticated Remote Code Execution in HPE Networking Fabric Composer Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity High CVE-2026-73715Unauthenticated Denial-of-Service (DoS) Vulnerability in the API of HPE Networking Fabric Composer Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity High CVE-2026-73714Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer API Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity High CVE-2026-73713Local Privilege Escalation Vulnerabilities in HPE Networking Fabric Composer Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity High CVE-2026-73712Unauthenticated Remote Code Execution in HPE Networking Fabric Composer API Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity High CVE-2026-73711Unauthenticated Privilege Escalation allows Administrative Access in HPE Networking Fabric Composer API Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity High CVE-2026-73710Unauthenticated Denial of Service Vulnerabilities in API Endpoint of HPE Networking Fabric Composer Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity High CVE-2026-73709Unauthenticated Remote Code Execution during HPE Networking Fabric Composer Installation Process Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity High CVE-2026-73708Fault in Business Logic allows Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity High CVE-2026-73707Authenticated Privilege Escalation via Broken Access Control in HPE Networking Fabric Composer API Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity High CVE-2026-73706Authentication Bypass in the API of HPE Networking Fabric Composer allows Data Exposure and Unauthorized Changes Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity High CVE-2026-73705Authenticated Arbitrary File Write leads to Remote Code Execution in HPE Networking Fabric Composer Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity High CVE-2026-73704Authenticated Command Injection Leading to Administrative Access in HPE Networking Fabric Composer API Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity High CVE-2026-73703Unauthenticated Stored Cross-Site Scripting (XSS) Vulnerability in HPE Networking Fabric Composer Web-Based Management Interface Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity High CVE-2026-73745Unauthenticated Limited Information Disclosure allows Data Exposure in the API of HPE Networking Fabric Composer Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity Low CVE-2026-73702Authenticated Privilege Escalation Vulnerability in the API of HPE Networking Fabric Composer Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity High CVE-2026-73701Unauthenticated Remote Code Execution in HPE Networking Fabric Composer Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity Critical CVE-2026-73700Authenticated Stored Cross-Site Scripting Vulnerability (XSS) in HPE Networking Fabric Composer Web-Based Management Interface Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity Critical CVE-2026-19766Authentication Bypass leads to Administrative control of adjacent network hosts in HPE Networking Fabric Composer Exploitation status Not known exploited Fix Not confirmed Affected product F Fabric Composer Published 09/01/2026 Severity Critical CVE-2026-63457Exploitation status Not known exploited Fix YesAffected product H HPE Integrated Lights-Out 6 (iLO 6) Published 08/05/2026 Severity Medium CVE-2026-63456Authentication bypass via spoofed HTTP headers Orchestrator REST API Exploitation status Not known exploited Fix YesAffected product E EdgeConnect SD-WAN Orchestrator Published 08/04/2026 Severity Critical CVE-2026-63455Authentication bypass via spoofed HTTP headers Orchestrator REST API Exploitation status Not known exploited Fix YesAffected product E EdgeConnect SD-WAN Orchestrator Published 08/04/2026 Severity Critical CVE-2026-44879Authenticated Command Injection allows arbitrary command execution in CLI Interface Exploitation status Not known exploited Fix Not confirmed Affected product E EdgeConnect SD-WAN Gateway (ECOS) Published 07/21/2026 Severity High CVE-2026-44878Authenticated Path Traversal allows Unauthorized Access in Web Interface Exploitation status Not known exploited Fix Not confirmed Affected product E EdgeConnect SD-WAN Gateway (ECOS) Published 07/21/2026 Severity High CVE-2026-63454Authenticated Path Traversal Vulnerability Leads to Remote Code Execution in AOS-CX Exploitation status Not known exploited Fix YesAffected product A AOS-CX Published 07/21/2026 Severity High CVE-2026-63453Authenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX Exploitation status Not known exploited Fix YesAffected product A AOS-CX Published 07/21/2026 Severity High CVE-2026-44880Low-Privilege Authenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX Exploitation status Not known exploited Fix YesAffected product A AOS-CX Published 07/21/2026 Severity High CVE-2026-44877Unauthenticated Remote Disclosure of Cryptographic Secrets Exploitation status Not known exploited Fix Not confirmed Affected product H HPE Networking Instant On Published 07/07/2026 Severity Medium