HEWLETT Packard Enterprise addressed 10 vulnerabilities in its Networking Analytics and Location Engine (ALE) platform on 22 September 2026. The flaws affect ALE versions 5.0.0.0 and earlier, including unsupported branches. Two vulnerabilities have a CVSS v3 score of 9.8: CVE-2026-76708, involving unauthenticated remote access through static, hard-coded credentials, and CVE-2026-76709, which permits unauthenticated remote arbitrary file writing through an internal administrative component.
Because the affected process has elevated privileges, successful exploitation could allow attackers to overwrite sensitive system binaries and take control of the server.
The other issues include sensitive information disclosure, data injection and exposure of password hashes through an unprotected API. The article says these weaknesses could reveal site hierarchy and client-device information, although it does not report confirmed exploitation. HPE stated that it was unaware of public discussion or exploit code targeting the vulnerabilities when its advisory was released, and the roundup lists none as actively exploited. HPE Networking hardware lines outside ALE are not affected by these specific flaws.
Administrators should upgrade to ALE version 5.1.0.0, which HPE released to address the vulnerabilities. Where immediate updating is not possible, the article recommends isolating the management interface, placing administrative traffic on a dedicated layer 2 VLAN and blocking untrusted incoming connections with strict firewall rules.