CVE-2026-76746: Unauthenticated Adjacent Buffer Overflow Vulnerability Leading to Information Disclosure in AOS-S
Published Oct 6, 2026
·Updated
An unauthenticated buffer overflow vulnerability exists in AOS-S. Successful exploitation could allow an unauthenticated adjacent attacker to expose sensitive memory contents and cause a denial of service on the affected device.
Affected Software
1 affected component
HPE AOS-S
Event History
Oct 6, 2026
CVE Published
via MITRE·07:06 PM
Data Sourced
via MITRE·07:06 PM
DescriptionSeverity
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require authentication or user interaction?
No. The vulnerability is exploitable without authentication and does not require user interaction.
2
Who is positioned to exploit the issue?
An attacker must be adjacent to the affected AOS-S device. The provided data does not identify affected versions, configurations, or compensating mitigations.
3
What are the potential effects of successful exploitation?
Successful exploitation could disclose sensitive memory contents and cause a denial of service on the affected device.