CVE-2026-76745 PUBLISHED

Unauthenticated Adjacent Memory Corruption Vulnerabilities Leading to Remote Code Execution in AOS-S

Assigner: hpe
Reserved: 19.08.2026 Published: 06.10.2026 Updated: 06.10.2026

Memory corruption vulnerabilities exist in AOS-S that are reachable by an unauthenticated adjacent attacker. Successful exploitation could allow an attacker to execute arbitrary code.

Metrics

CVSS Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 9.6

Product Status

Vendor Hewlett Packard Enterprise (HPE)
Product AOS-Switch (AOS-S)
Versions Default: affected
  • affected from 16.11.0000 to 16.11.0031 (incl.)

Credits

  • Internal security research (HPE Networking). reporter

References