Junglewise Threat Intelligence

CVE-2026-76685: HPE proxy packet processing integer overflow

CVE-2026-76685 · Severity: high · CVSS 8.1 · Published 2026-09-15

Executive brief

A proxy component used to route network traffic improperly processes malformed or truncated input, leading to an integer overflow condition. An unauthenticated attacker on the network can trigger this flaw by sending specially crafted packets, potentially causing the service to crash (denial-of-service) or execute arbitrary code with the same privileges as the proxy process.

Technical details

The vulnerability exists in the proxy packet processing logic where integer overflow occurs during malformed or truncated input handling. The flaw is triggered by an unauthenticated remote attacker providing specially crafted input that overflows an integer, leading to a subsequent buffer overflow. This can result in remote code execution or denial-of-service. The attack vector is network-based and requires no authentication or user interaction. Patches are expected to be available from HPE through the referenced support documentation.

Affected products

  • HPE Proxy Component <UNKNOWN>

Timeline

  • 2026-09-15: disclosed

References