Hewlett Packard Enterprise has fixed 18 vulnerabilities in its HPE Networking Instant On access points. Instant On is the company's cloud-managed Wi-Fi line for small offices, shops, clinics and branch sites. Security bulletin HPESBNW05150, published on 29 September 2026, covers Instant On 3.4.1.0 and below. Two of the flaws are rated CVSS 9.8 and let an attacker with no credentials execute code on the access point over the network. Another three are rated 9.6 and need only a foothold on the adjacent network. The fix is Instant On 3.4.2.0. HPE says the Instant On cloud management portal applies it automatically, so the main job for administrators is to confirm that every access point has actually updated.

The Two CVSS 9.8 Remote Code Execution Flaws

  • CVE-2026-76721: unauthenticated buffer overflow (9.8). HPE says a buffer overflow "exists in the affected interface" that "could allow an unauthenticated remote attacker to run arbitrary code on the underlying host". Successful exploitation runs code "as a privileged user on the underlying operating system". Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
  • CVE-2026-76722: uncontrolled format strings (9.8). HPE describes several format-string flaws in the same "affected interface". It says they could let an unauthenticated remote attacker "run arbitrary commands on the underlying host", with outcomes ranging from denial of service to "potential remote code execution". The CVE groups two internal findings.

HPE does not name "the affected interface", and it has not published request formats, ports or code-level detail. Its workaround is to restrict the web-based management interfaces. That suggests management-plane exposure is the main concern, but HPE does not say outright that this is the vulnerable interface, so treat it as an inference.

Adjacent-Network Flaws: PAPI Command Injection and Management Bypass

Three critical flaws use the adjacent attack vector (AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, 9.6). An attacker on the same layer-2 segment, such as a guest Wi-Fi user or a compromised device on the LAN, needs no credentials:

  • CVE-2026-76723: buffer overflows (seven internal findings) that allow command execution on the underlying OS.
  • CVE-2026-76724: command injection in the access point's command-line interface, reachable through the PAPI protocol by "sending specially crafted packets". Commands run as a privileged user.
  • CVE-2026-76725: authentication bypass in "a management protocol" that HPE says could lead to "a complete bypass of security restrictions, potentially leading to remote code execution with elevated privileges".

A separate PAPI authentication bypass, CVE-2026-76730 (6.5), lets an adjacent attacker send unauthorised traffic to the device. CVE-2026-76726 (8.1) is an authentication bypass in an API endpoint. HPE says that, "if certain preconditions outside of the attacker's control are met", it could give an unauthenticated remote attacker "unauthorized access to restricted networks". In a deployment that uses network segmentation, that is a meaningful risk. CVE-2026-76731 (6.5) is an authentication bypass in the captive portal.

The remaining flaws need high privileges or local access. They include:

  • Authenticated command injection (CVE-2026-76727, 7.2).
  • Authenticated SSRF that leads to command execution (CVE-2026-76728, 7.2).
  • A format string in the API (CVE-2026-76729, 6.6).
  • Local privilege escalation in a daemon (CVE-2026-76732, 6.4).
  • Low-severity denial-of-service, information disclosure and path traversal issues (CVE-2026-76733 to CVE-2026-76738).

Exploitation Status

HPE says the flaws "were generally discovered by internal security research at HPE Networking". In the bulletin's words, HPE "is not aware of any public discussion or exploit code that targets the listed vulnerabilities as of the release date of this advisory". It adds: "Customers are strongly urged to patch their instances due to the complexity, breadth, and impact of these vulnerabilities." None of the CVEs is in CISA's Known Exploited Vulnerabilities catalog, and HPE has published no indicators of compromise.

Affected and Fixed Versions

CVEType (per HPE)CVSS 3.1Attacker position
CVE-2026-76721Buffer overflow, RCE9.8Remote, unauthenticated
CVE-2026-76722Format string, RCE/DoS9.8Remote, unauthenticated
CVE-2026-76723Buffer overflows, RCE9.6Adjacent, unauthenticated
CVE-2026-76724CLI command injection via PAPI9.6Adjacent, unauthenticated
CVE-2026-76725Management protocol auth bypass9.6Adjacent, unauthenticated
CVE-2026-76726API endpoint auth bypass, network access8.1Remote, unauthenticated (preconditions)
CVE-2026-76727 / -76728Command injection / SSRF to RCE7.2Remote, high privilege
CVE-2026-76729 to -76738Format string, auth bypass, LPE, DoS, info disclosure, path traversal6.6 to 2.7Mixed

Affected: Instant On 3.4.1.0 and below. The bulletin lists the AP11 under supported software versions. Fixed: Instant On 3.4.2.0 and above. HPE adds that software versions past End of Maintenance are "presumed to be affected" and are not covered. For versions past End of Support, HPE has not assessed exposure and says they "should be considered potentially impacted".

Defensive Playbook for Instant On Deployments

  1. Confirm the automatic update has landed. HPE says fixed software "will be applied to the affected APs automatically by the Instant On cloud management portal". Check the reported software version of every site and access point in the Instant On portal or mobile app, and look for any device still on 3.4.1.0 or earlier. Pay particular attention to devices that are offline, have lost cloud connectivity, or sit at sites with unusual maintenance windows.
  2. Apply HPE's workaround where updates lag. HPE recommends restricting web-based management interfaces "to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above", with accounting controls that track and log user activity.
  3. Separate guest and IoT clients from the management plane. Four of the flaws, three of them critical, need only adjacent-network access. Make sure guest SSIDs and untrusted wired ports cannot reach access point management addresses, and that client isolation is enabled on guest networks.
  4. Retire unsupported hardware. Access points on software past End of Maintenance or End of Support will not receive a fix that HPE has assessed. Replace or isolate them.
  5. Review administrator accounts. Several lower-rated flaws need an authenticated administrator. Remove unused Instant On administrator accounts, and enforce strong, unique credentials and multi-factor authentication on the cloud portal account.

Branch Wi-Fi equipment is rarely watched as closely as data-centre gear. An access point running attacker code as a privileged user sits inside the network perimeter, with a view of every client that connects to it.