CVE-2026-76722: Uncontrolled Format String Vulnerabilities lead to Remote Code Execution or Denial-of-Service in HPE Networking Instant ON APs
Published Sep 29, 2026
·Updated
Uncontrolled Format string vulnerabilities exist in the affected interface of HPE Networking Instant ON APs that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation could result in a Denial-of-service or potential remote code execution.
Affected Software
1 affected component
HPE Networking Instant On APs
Event History
Sep 29, 2026
CVE Published
via MITRE·07:28 PM
Data Sourced
via MITRE·07:28 PM
DescriptionSeverity
Data Sourced
via NVD·08:17 PM
DescriptionSeverity
Frequently Asked Questions
1
Who can exploit this issue?
An unauthenticated remote attacker can exploit the vulnerable affected interface. No privileges or user interaction are required.
2
What impact could successful exploitation have?
Successful exploitation could allow arbitrary commands to be run on the underlying host. It could result in denial of service or potential remote code execution.