CVE-2026-76685
—Unauthenticated Integer-Overflow RCE in HPE Proxy Packet Processing
CVE-2026-76685 is an integer overflow in the proxy packet processing logic of an HPE component, triggered when the service parses malformed or truncated packets. An unauthenticated, remote attacker can send specially crafted input to overflow a buffer, potentially achieving remote code execution or crashing the service for denial-of-service. The CVSS 3.1 base score is 8.1 (high), with high impact on confidentiality, integrity, and availability, though exploitation requires high attack complexity (AV:N/AC:H/PR:N/UI:N). The flaw affects HPE products containing the vulnerable proxy component; specific product names and version ranges were not included in the provided data, so defenders should consult the HPE advisory (the CNA is [email protected]). No public proof-of-concept exists and the issue is not listed in the CISA Known Exploited Vulnerabilities catalog, so no in-the-wild exploitation is known.
What to do: Apply the patched software/firmware version specified in the HPE security advisory for the affected product as soon as it is available. In the interim, restrict network access to the proxy service so only trusted sources can reach it, and enable logging to detect malformed-packet inputs or unexpected crashes of the component. If the proxy is internet-facing, consider placing it behind a firewall or VPN until the fix is deployed.
| HPE | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability exists in the proxy packet processing logic of the affected component where it improperly processes malformed or truncated input. An unauthenticated remote attacker could exploit this vulnerability by providing specially crafted input that triggers an integer overflow. Successful exploitation could result in a buffer overflow, potentially leading to remote code execution or denial-of-service.
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.