Vulnerabilities & Exploits

HPE iLO Firmware Flaw Opens the Management Plane

The CVE Program assigned CVE-2026-79820 to a critical remote user validation failure in HPE Integrated Lights-Out (iLO) 7 firmware, affecting version 1.25.00. HPE iLO is the out-of-band management layer used to administer servers.

The flaw sits in the firmware’s user-checking step: a remote caller can be accepted without properly proving who it is. Because that path is separate from the host operating system, hardening the OS does not cover the management interface if iLO is reachable.

For HPE server fleets, the exposure is on the control plane, not just the machine workload. If the interface is exposed in your environment, the risk remains even when the operating system itself is locked down.

1 source · 16h ago

CVE-2026-79820

NVD KEV

CVSS 9 CRITICAL: a remote user validation failure vulnerability exists in HPE Integrated Lights-Out (iLO) 7 firmware.

Timeline

Sources

Part of the PlainSec briefing for 2026-10-06

Every edition of this story: HPE iLO Firmware Flaw Opens the Management Plane

More from today