Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 30 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 30 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) instant On |
|
| Vendors & Products |
Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) instant On |
Tue, 29 Sep 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-134 |
Tue, 29 Sep 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A format string vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to cause memory corruption with a modified input. Successful exploitation could allow an attacker to provoke a denial-of-service condition or remote code execution in the affected system function. | |
| Title | Authenticated Format String Vulnerability allows Memory Corruption in HPE Networking Instant ON API Endpoint | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: hpe
Published:
Updated: 2026-09-30T20:33:11.640Z
Reserved: 2026-08-19T16:13:18.140Z
Link: CVE-2026-76729
Updated: 2026-09-30T20:33:02.171Z
Status : Awaiting Analysis
Published: 2026-09-29T20:17:25.073
Modified: 2026-09-30T21:17:14.377
Link: CVE-2026-76729
No data.
OpenCVE Enrichment
Updated: 2026-09-30T20:36:39Z
-
CWE-134
Use of Externally-Controlled Format String