HP E has disclosed 18 vulnerabilities in its Instant ON access points, with five deemed Critical. The most severe flaws are CVSS 9.8 issues, CVE-2026-76721 and CVE-2026-76722, both not yet exploited at the time of the advisory. The batch also includes two other 9.6 items and several medium to low-severity flaws. HPE’s Instant ON 3.4.2[.]0 and later fixes address all of these vulnerabilities, and administrators are urged to apply the update promptly.
The affected product line is HPE’s cloud-managed Wi‑Fi for small businesses, where an compromised access point on the local network can give an attacker a strong foothold.
Details from the advisory show multiple ways an attacker could compromise devices. CVE-2026-76721 involves an unauthenticated buffer overflow in an exposed interface, potentially allowing remote code execution on the underlying host. CVE-2026-76722 features format-string weaknesses that can lead to remote code execution or denial of service.
Other high-severity flaws require local access on the same network segment, including buffer overflows (CVE-2026-76723), a CLI command injection via the PAPI protocol (CVE-2026-76724), and an authentication bypass in a management protocol (CVE-2026-76725). Additional issues cover an API authentication bypass (CVE-2026-76726) and further injections or SSRF-type weaknesses (CVE-2026-76727 to CVE-76728). No exploitation in the wild is confirmed, and affected versions run up to 3.4.1[.]0 or older. Immediate patching to 3.4.2[.]0 is advised, with interim mitigations such as segmenting management interfaces.