HPE has released fixes for two critical flaws across its server and network management tools. The first, CVE-2026-79820, affects iLO 7 and could let a remote attacker obtain administrative access without login, when used with HPE Compute Ops Management (COM). The second, CVE-2026-79842, is an authentication bypass in HPE Intelligent Management Center (iMC) that could be exploited remotely without credentials.
HPE notes that there has been no reported exploitation in the wild or public PoCs at this time, but the vulnerabilities carry high severities (CVSSv3: 9.0 for CVE-2026-79820 and 9.1 for CVE-2026-79842).
Affected versions and the patches are as follows: iLO 7 version 1.25.00 is vulnerable, with a fix available in 1.25.01 or later. iMC versions prior to 7.3 E0713 are affected, with the fix deployed in 7.3 E0713. Organisations are advised to update promptly; until patches are applied, HPE recommends isolating iLO and iMC interfaces on separate management networks to limit exposure. The iLO flaw was identified by HPE internal testing, while the iMC issue was reported to HPE by researcher Nhi Nguyen.
The combined impact of taking control of iLO or bypassing iMC authentication could give an attacker broad reach within an environment, underscoring the need for timely updates across affected systems.