Vulnerabilities · 9h ago
HPE disclosed 18 vulnerabilities in Instant On APs running 3.4.1.0 and earlier, including 10 named CVEs that can lead to code execution, command execution, authentication bypass, SSRF, or denial of service. HPE says the fixes arrive in version 3.4.2.0.
The catch is how those fixes land: only APs managed through the Instant On cloud portal get corrected automatically. Offline, standalone, or end-of-life APs can stay vulnerable even after a normal update cycle, so the exposure is partly about fleet coverage, not just software version.
For operators with mixed or unmanaged APs, the remaining risk sits on devices outside the cloud-managed path, and management-plane flaws can matter as much as wireless disruption. The report does not settle how many exposed APs are not enrolled in Instant On management.
CVEs in this update
10 CVEs
Across Instant ON.
5 critical · 3 high · 2 medium · 0 low
0 in CISA KEV · 0 with EPSS above 1%
Highest severity: CVE-2026-76721 · 9.8 CRITICAL
1 source covering this story
Múltiples vulnerabilidades en Instant On APs de HPE Networking
HPE Networking ha publicado 18 vulnerabilidades: 5 de severidad crítica, 3 de severidad alta, 7 de sev
Part of the PlainSec briefing for 2026-09-30