SPOJENO PŘES CVE EPSS 0.01 (nejvyšší)
HPE Networking Analytics and Location Engine - Multiple Severe Vulnerabilities
Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-76708, CVE-2026-76709, CVE-2026-76710, CVE-2026-76711, CVE-2026-76712, CVE-2026-76713, CVE-2026-76714, CVE-2026-76715, CVE-2026-76716, CVE-2026-76717, Summary: HPE has disclosed multiple vulnerabilities in Networking Analytics and Location Engine (ALE). The vulnerabilities include unauthenticated remote unauthorized access, arbitrary file write, sensitive-information disclosure, data…
HPE FI FR
CVE v události 10
| CVE | hodnocení | KEV | EPSS |
|---|---|---|---|
| CVE-2026-76708 | 9.8 3.1 · hpe | – | 0.01 |
| CVE-2026-76709 | 9.8 3.1 · hpe | – | 0.01 |
| CVE-2026-76710 | 7.5 3.1 · hpe | – | 0.01 |
| CVE-2026-76711 | 7.5 3.1 · hpe | – | 0.00 |
| CVE-2026-76712 | 7.3 3.1 · hpe | – | 0.00 |
| CVE-2026-76713 | 7.2 3.1 · hpe | – | 0.01 |
| CVE-2026-76714 | 7.2 3.1 · hpe | – | 0.01 |
| CVE-2026-76715 | 7.1 3.1 · hpe | – | 0.00 |
| CVE-2026-76716 | 5.3 3.1 · hpe | – | 0.01 |
| CVE-2026-76717 | 5.3 3.1 · hpe | – | 0.00 |
Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.8.
Jak se o tom psalo 2
-
· NCSC-FI FI nadpis události
HPE Networking Analytics and Location Engine - Multiple Severe Vulnerabilities
Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-76708, CVE-2026-76709, CVE-2026-76710, CVE-2026-76711, CVE-2026-76712, CVE-2026-76713, CVE-2026-76714, CVE-2026-76715, CVE-2026-76716, CVE-2026-76717, Summary: HPE has disclosed multiple vulnerabilities in Networking Analytics and Location Engine (ALE). The vulnerabilities include unauthenticated remote unauthorized access, arbitrary file write, sensitive-information disclosure, data…
-
· CERT-FR – avis FR
Multiples vulnérabilités dans les produits HPE Aruba Networking (23 septembre 2026)
De multiples vulnérabilités ont été découvertes dans les produits HPE Aruba Networking. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.