Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-76743: HPE AOS‑S management interface could let outsiders log in without permission

CVE-2026-76743 · published 3 days ago
Summary

The web‑based management console of HPE AOS‑S switches can be tricked into skipping its login checks under certain conditions. An attacker on the network could then reach the system without a valid username or password, potentially viewing or changing settings. Apply the latest security update from HPE as soon as possible and limit network access to the management console.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
hewlett packard enterprise (hpe) aos-switch (aos-s) <= 16.11.0031
Original advisory text
Authentication Bypass Vulnerability in the Management Interface of AOS-S
A vulnerability have been identified in the management interface of AOS-S that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to gain unauthorized access to the affected system.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-287Improper Authentication
Timeline
Published6 Oct 2026
Updated9 Oct 2026
First seen6 Oct 2026
Sources
CVE-2026-76743 · MITRE
Track software like this
Free during beta