OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-76722

CRITICAL · CVSS 9.8 EPSS 0.54% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

Uncontrolled format string vulnerabilities in HPE Networking Instant ON access points allow unauthenticated remote attackers to execute arbitrary commands on the host system. This critical flaw, with a CVSS score of 9.8, could lead to denial-of-service conditions or remote code execution. Organizations using these access points should prioritize immediate remediation to mitigate potential exploitation risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-76722
Severity
CRITICAL
CVSS
9.8
EPSS
0.54%

Original NVD Description

Uncontrolled Format string vulnerabilities exist in the affected interface of HPE Networking Instant ON APs that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation could result in a Denial-of-service or potential remote code execution.