OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-76724

CRITICAL · CVSS 9.6 EPSS 1.02% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

A critical command injection vulnerability in the CLI of HPE Networking Instant ON APs allows unauthenticated adjacent attackers to send specially crafted packets, enabling them to execute arbitrary commands with privileged access on the underlying operating system. Organizations using these affected access points should prioritize immediate remediation to mitigate the risk of unauthorized system control and potential data breaches. Network administrators and security teams should assess their environments for exposure and apply necessary patches or mitigations promptly.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-76724
Severity
CRITICAL
CVSS
9.6
EPSS
1.02%

Original NVD Description

A command injection vulnerability exists in CLI of the affected HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to perform command injection by sending specially crafted packets. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.