SecAlerts
H

HPE

Security Risk Profile

56
/100
medium

Security Risk Score

Comprehensive risk assessment based on 396 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from August 10, 2002 to present

396
Total CVEs
260
Critical+High
6
Exploited
217
Unpatched

Threat Assessment

Avg CVSS
7.5
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
217
Critical/High
Risk Level
56/100
medium
⚠️ 6 Active Exploits🆕 10Fresh (<7d)📈 133 in Last 30 Days

Severity Distribution

Critical
61
High
199
Medium
118
Low
10

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
12

Age Distribution

Common Weaknesses (CWE)

1
Buffer Overflow
40
2
Command Injection
33
3
XSS
23
4
Path Traversal
22
5
Infoleak
21

Most Affected Products

1. NTP ntp663
2. HPE Arubaos-cx270
3. Arubanetworks Edgeconnect Sd-wan Orchestrator152
4. HPE Edgeconnect Operating System152
5. Arubanetworks Fabric Composer52

Recent Vulnerabilities

See more →
CVE-2026-76717
CVSS 5.3medium

Unauthenticated Remote Sensitive Information Disclosure Vulnerability in HPE Networking Analytics and Location Engine (ALE)

Sep 22, 2026🔧 No Patch
CVE-2026-76716
CVSS 5.3medium

Unauthenticated Remote Unauthorized Access and Denial of Service Vulnerabilities in HPE Networking Analytics and Location Engine (ALE)

Sep 22, 2026🔧 No Patch
CVE-2026-76715
CVSS 7.1high

Unauthenticated Man-in-the-Middle Attach Leads to Remote Code Execution Vulnerability in HPE Networking Analytics and Location Engine (ALE)

Sep 22, 2026🔧 No Patch
CVE-2026-76714
CVSS 7.2high

Authenticated Remote Code Execution with Elevated Privileges Vulnerability in HPE Networking Analytics and Location Engine (ALE)

Sep 22, 2026🔧 No Patch
CVE-2026-76712
CVSS 7.3high

Unauthenticated Remote Unauthorized Access, Information Disclosure, and Denial of Service Vulnerabilities in HPE Networking Analytics and Location Engine (ALE)

Sep 22, 2026🔧 No Patch
CVE-2026-76713
CVSS 7.2high

Authenticated Remote File System Access Vulnerability in HPE Networking Analytics and Location Engine (ALE)

Sep 22, 2026🔧 No Patch
CVE-2026-76711
CVSS 7.5high

Unauthenticated Remote Data Injection Vulnerability in HPE Networking Analytics and Location Engine (ALE)

Sep 22, 2026🔧 No Patch
CVE-2026-76710
CVSS 7.5high

Unauthenticated Remote Sensitive Information Disclosure Vulnerability in HPE Networking Analytics and Location Engine (ALE)

Sep 22, 2026🔧 No Patch
CVE-2026-76709
CVSS 9.8critical

Unauthenticated Remote Arbitrary File Write Vulnerability in HPE Networking Analytics and Location Engine (ALE)

Sep 22, 2026🔧 No Patch
CVE-2026-76708
CVSS 9.8critical

Unauthenticated Remote Unauthorized Access Vulnerability in HPE Networking Analytics and Location Engine (ALE)

Sep 22, 2026🔧 No Patch

Monitor HPE in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.