HPE Instant On AP Flaws Let Unauthenticated Attackers Execute Arbitrary Commands
HPE patched 18 Instant On AP flaws, including unauthenticated remote code execution scored CVSS 9.8.
HPE advisory HPESBNW05150 covers 18 vulnerabilities in Networking Instant On access points running software 3.4.1.0 and earlier. CVE-2026-76721 and CVE-2026-76722, both CVSS 9.8, allow unauthenticated remote buffer-overflow code execution or format-string command execution. Three additional critical flaws scored 9.6 require adjacent-network access and can enable command injection, authentication bypass, or remote code execution. HPE said it was unaware of public exploit code as of September 29 and recommends upgrading to 3.4.2.0 or later, with automatic updates for eligible cloud-managed devices.