{"schema_version":1,"title":"Hewlett Packard Enterprise vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 9 vulnerabilities in Hewlett Packard Enterprise: 0 in the last 7 days and 6 in the last 90 days, 5 of them critical and 3 exploited in the wild. The most recent, CVE-2026-76704, was published on 15 September 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/hewlett-packard-enterprise","json_url":"https://junglewise.ai/threats/vendors/hewlett-packard-enterprise.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/hewlett-packard-enterprise","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":3,"all_time":9,"critical":5,"exploited":3,"last_7_days":0,"last_30_days":6,"last_90_days":6,"last_365_days":7},"latest":[{"cve":"CVE-2026-76704","cvss":5.5,"epss":0.0033,"slug":"cve-2026-76704-a-vulnerability-in-the-web-based-management-interface-of-the","title":"Hewlett Packard Enterprise EdgeConnect SD-WAN Orchestrator stored XSS in web management interface","severity":"medium","exploited":false,"published_at":"2026-09-15T20:17:54.943+00:00","url":"https://junglewise.ai/threats/cve-2026-76704-a-vulnerability-in-the-web-based-management-interface-of-the"},{"cve":"CVE-2026-76688","cvss":7.5,"epss":0.0038,"slug":"cve-2026-76688-vulnerabilities-have-been-identified-in-the-web-based-management","title":"Hewlett Packard Enterprise EdgeConnect SD-WAN Orchestrator auth bypass in management interface","severity":"high","exploited":false,"published_at":"2026-09-15T20:17:50.797+00:00","url":"https://junglewise.ai/threats/cve-2026-76688-vulnerabilities-have-been-identified-in-the-web-based-management"},{"cve":"CVE-2026-76681","cvss":8.5,"epss":0.0035,"slug":"cve-2026-76681-a-vulnerability-in-the-api-of-edgeconnect-sd-wan-orchestrator","title":"Hewlett Packard Enterprise EdgeConnect SD-WAN Orchestrator API privilege escalation","severity":"high","exploited":false,"published_at":"2026-09-15T20:17:50+00:00","url":"https://junglewise.ai/threats/cve-2026-76681-a-vulnerability-in-the-api-of-edgeconnect-sd-wan-orchestrator"},{"cve":"CVE-2026-76675","cvss":9.1,"epss":0.0145,"slug":"cve-2026-76675-hewlett-packard-enterprise-edgeconnect-command-injection-in-cli","title":"Hewlett Packard Enterprise EdgeConnect command injection in CLI","severity":"critical","exploited":false,"published_at":"2026-09-15T20:17:49.32+00:00","url":"https://junglewise.ai/threats/cve-2026-76675-hewlett-packard-enterprise-edgeconnect-command-injection-in-cli"},{"cve":"CVE-2026-76673","cvss":9.8,"epss":0.0061,"slug":"cve-2026-76673-vulnerabilities-have-been-identified-in-the-api-of-edgeconnect-sd","title":"Hewlett Packard Enterprise EdgeConnect SD-WAN Orchestrator authentication bypass in API","severity":"critical","exploited":false,"published_at":"2026-09-15T20:17:49.09+00:00","url":"https://junglewise.ai/threats/cve-2026-76673-vulnerabilities-have-been-identified-in-the-api-of-edgeconnect-sd"},{"cve":"CVE-2026-73786","cvss":7.5,"epss":0.0057,"slug":"cve-2026-73786-hewlett-packard-enterprise-cppm-dos-in-web-management-interface","title":"Hewlett Packard Enterprise CPPM DoS in web management interface","severity":"high","exploited":false,"published_at":"2026-09-09T20:20:33.493+00:00","url":"https://junglewise.ai/threats/cve-2026-73786-hewlett-packard-enterprise-cppm-dos-in-web-management-interface"},{"cve":"CVE-2025-37164","cvss":10,"epss":0.7357,"slug":"cve-2025-37164-hpe-oneview-code-injection-remote-code-execution","title":"HPE OneView code injection remote code execution","severity":"critical","exploited":true,"published_at":"2026-01-07T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-37164-hpe-oneview-code-injection-remote-code-execution"},{"cve":"CVE-2013-4810","cvss":9.8,"slug":"cve-2013-4810-hp-multiple-products-remote-code-execution-vulnerability","title":"HP Multiple Products Remote Code Execution Vulnerability","severity":"critical","exploited":true,"published_at":"2022-03-25T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2013-4810-hp-multiple-products-remote-code-execution-vulnerability"},{"cve":"CVE-2005-2773","cvss":9.8,"slug":"cve-2005-2773-hp-openview-network-node-manager-remote-code-execution","title":"HP OpenView Network Node Manager Remote Code Execution Vulnerability","severity":"critical","exploited":true,"published_at":"2022-03-25T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2005-2773-hp-openview-network-node-manager-remote-code-execution"}],"vendor":{"hub":true,"name":"Hewlett Packard Enterprise","slug":"hewlett-packard-enterprise","homepage":"https://www.hpe.com/","description":"An enterprise information technology company providing servers, storage, networking, and software solutions.","url":"https://junglewise.ai/threats/vendors/hewlett-packard-enterprise"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-14","critical":2,"exploited":0,"vulnerabilities":5},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2025-37164","cvss":10,"epss":0.7357,"slug":"cve-2025-37164-hpe-oneview-code-injection-remote-code-execution","title":"HPE OneView code injection remote code execution","severity":"critical","exploited":true,"published_at":"2026-01-07T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-37164-hpe-oneview-code-injection-remote-code-execution"},{"cve":"CVE-2013-4810","cvss":9.8,"slug":"cve-2013-4810-hp-multiple-products-remote-code-execution-vulnerability","title":"HP Multiple Products Remote Code Execution Vulnerability","severity":"critical","exploited":true,"published_at":"2022-03-25T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2013-4810-hp-multiple-products-remote-code-execution-vulnerability"},{"cve":"CVE-2005-2773","cvss":9.8,"slug":"cve-2005-2773-hp-openview-network-node-manager-remote-code-execution","title":"HP OpenView Network Node Manager Remote Code Execution Vulnerability","severity":"critical","exploited":true,"published_at":"2022-03-25T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2005-2773-hp-openview-network-node-manager-remote-code-execution"},{"cve":"CVE-2026-76673","cvss":9.8,"epss":0.0061,"slug":"cve-2026-76673-vulnerabilities-have-been-identified-in-the-api-of-edgeconnect-sd","title":"Hewlett Packard Enterprise EdgeConnect SD-WAN Orchestrator authentication bypass in API","severity":"critical","exploited":false,"published_at":"2026-09-15T20:17:49.09+00:00","url":"https://junglewise.ai/threats/cve-2026-76673-vulnerabilities-have-been-identified-in-the-api-of-edgeconnect-sd"},{"cve":"CVE-2026-76675","cvss":9.1,"epss":0.0145,"slug":"cve-2026-76675-hewlett-packard-enterprise-edgeconnect-command-injection-in-cli","title":"Hewlett Packard Enterprise EdgeConnect command injection in CLI","severity":"critical","exploited":false,"published_at":"2026-09-15T20:17:49.32+00:00","url":"https://junglewise.ai/threats/cve-2026-76675-hewlett-packard-enterprise-edgeconnect-command-injection-in-cli"},{"cve":"CVE-2026-76681","cvss":8.5,"epss":0.0035,"slug":"cve-2026-76681-a-vulnerability-in-the-api-of-edgeconnect-sd-wan-orchestrator","title":"Hewlett Packard Enterprise EdgeConnect SD-WAN Orchestrator API privilege escalation","severity":"high","exploited":false,"published_at":"2026-09-15T20:17:50+00:00","url":"https://junglewise.ai/threats/cve-2026-76681-a-vulnerability-in-the-api-of-edgeconnect-sd-wan-orchestrator"},{"cve":"CVE-2026-73786","cvss":7.5,"epss":0.0057,"slug":"cve-2026-73786-hewlett-packard-enterprise-cppm-dos-in-web-management-interface","title":"Hewlett Packard Enterprise CPPM DoS in web management interface","severity":"high","exploited":false,"published_at":"2026-09-09T20:20:33.493+00:00","url":"https://junglewise.ai/threats/cve-2026-73786-hewlett-packard-enterprise-cppm-dos-in-web-management-interface"},{"cve":"CVE-2026-76688","cvss":7.5,"epss":0.0038,"slug":"cve-2026-76688-vulnerabilities-have-been-identified-in-the-web-based-management","title":"Hewlett Packard Enterprise EdgeConnect SD-WAN Orchestrator auth bypass in management interface","severity":"high","exploited":false,"published_at":"2026-09-15T20:17:50.797+00:00","url":"https://junglewise.ai/threats/cve-2026-76688-vulnerabilities-have-been-identified-in-the-web-based-management"},{"cve":"CVE-2026-76704","cvss":5.5,"epss":0.0033,"slug":"cve-2026-76704-a-vulnerability-in-the-web-based-management-interface-of-the","title":"Hewlett Packard Enterprise EdgeConnect SD-WAN Orchestrator stored XSS in web management interface","severity":"medium","exploited":false,"published_at":"2026-09-15T20:17:54.943+00:00","url":"https://junglewise.ai/threats/cve-2026-76704-a-vulnerability-in-the-web-based-management-interface-of-the"}],"generated_at":"2026-09-26T11:07:00.153785+00:00","technologies":[{"name":"Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways","slug":"edgeconnect-sd-wan-gateways","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/edgeconnect-sd-wan-gateways"}]}