Hewlett Packard EnterpriseCVE-2026-44877
Hewlett Packard Enterprise HPE Networking Instant On: information disclosure
Medium6.5CVE-2026-44877 · Published Jul 7, 2026 · updated Jul 9, 2026
An unauthenticated remote disclosure vulnerability has been identified in HPE Networking Instant On 1830, 1930, and 1960 Switches. Successful exploitation of this vulnerability could allow an unauthenticated remote threat actor to access sensitive cryptographic secrets on a vulnerable system.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| HPE Networking Instant On Product | >= 3.0.0, <= 3.3.3 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-200
More Hewlett Packard Enterprise advisories
All Hewlett Packard Enterprise| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 4 | Hewlett Packard Enterprise EdgeConnect: information disclosure | Critical9.8 | No fix yet |
| Jul 21 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateway (ECOS): command injection | High7.2 | No fix yet |
| Jul 21 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateway: insecure permissions | High7.2 | No fix yet |
| Jul 21 | Hewlett Packard Enterprise AOS-CX: path traversal | High7.2 | 10.18.0001 |
| Jul 21 | Hewlett Packard Enterprise AOS-CX: buffer overflow | High7.2 | 10.18.0001 |
| Jul 21 | Hewlett Packard Enterprise AOS-CX: buffer overflow | High8.8 | 10.18.0001 |