On September 29, HPE published advisory HPESBNW05150 for 18 vulnerabilities affecting Networking Instant On access points. Five are rated critical. The advisory covers versions through 3.4.1.0; vulnerability tracking sources identify version 3.4.2.0 as the fixed release. The 18 CVE references run from CVE-2026-76721 through CVE-2026-76738; consult HPE's bulletin and the CERT-FR notice for each flaw's details and severity.
The flaws affect different components and attack scenarios, including remote code execution and security-control bypass. At the time of publication, HPE said it was not aware of public exploitation. This is distinct from vulnerabilities for which active exploitation has been observed.
Systems to check
Inventory all Instant On access points, including spare, test and remotely managed devices. Record each model, software version and management mode, then compare them with HPE's advisory. CVE descriptions and attack vectors differ; do not assume every flaw has the same impact.
Install the fixed release
Confirm in HPE release notes that 3.4.2.0 is available for your model and follow the official upgrade process. Schedule access point restarts, verify devices return online and confirm the firmware version afterward.
If an immediate update is not possible, restrict management interfaces to the administration network, segment the devices as HPE recommends and watch for unusual connection attempts. These steps reduce exposure but do not replace the patch.
Review network activity
After updating, review management logs, configuration changes and newly connected devices. Unexpected connections or restarts deserve investigation; by themselves, they do not prove exploitation.
How Soclyde fits
Soclyde does not update access points or secure Wi-Fi. Its vault can help a team keep administration accounts and infrastructure secrets organized under the team's control.
The takeaway
Inventory Instant On devices, check firmware and apply the fixed release using HPE's procedure. To organize technical accounts, read the team password management guide or contact Soclyde.



