B
今週中
HPE製の無線LANアクセスポイント「HPE Networking Instant On AP」において、18件の脆弱性
📌 一言でいうと
HPE製の無線LANアクセスポイント「HPE Networking Instant On AP」において、18件の脆弱性が公開されました。うち5件は「クリティカル」とされており、特権取得が可能なバッファオーバーフローや認証回避などの深刻な問題が含まれています。一部の脆弱性は隣接ネットワークから認証なしで攻撃が可能であり、迅速なアップデート適用が推奨されています。
🔍該当判定
- 社内でWi-Fiアクセスポイントに「HPE Networking Instant On AP」シリーズを利用している
- 社内ネットワークに「HPE製」の無線LAN親機(AP)を設置している
- 管理画面や設定アプリで「Instant On」という名称の製品を運用している
上記いずれにも該当しない → 静観でOK
✅該当時の対応
ベンダーが提供する最新のセキュリティアップデートを速やかに適用してください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】HPE Networking Instant On AP 脆弱性対応について
お疲れさまです。HPE製アクセスポイントの脆弱性に関する情報共有です。
■ 概要
HPE Networking Instant On APにおいて、CVSS v3.1スコア最大9.8のクリティカルな脆弱性が5件を含む計18件の脆弱性が報告されました。バッファオーバーフローやコマンドインジェクション、認証回避などにより、攻撃者が特権を取得したり任意のコードを実行したりする可能性があります。
■ 影響範囲
- 対象製品: HPE Networking Instant On AP
- 脆弱性: CVE-2026-76721, CVE-2026-76722 (CVSS 9.8), CVE-2026-76723, CVE-2026-76724, CVE-2026-76725 (CVSS 9.6) 等
■ 対応手順
1. 自社環境で利用している Instant On AP のバージョンを確認してください。
2. HPEが提供する最新のセキュリティアップデートを適用してください。
■ 参考情報
- HPE セキュリティアドバイザリ: HPESBNW05150 rev.1
対応優先度: 高
対応期限: 速やかに
お疲れさまです。HPE製アクセスポイントの脆弱性に関する情報共有です。
■ 概要
HPE Networking Instant On APにおいて、CVSS v3.1スコア最大9.8のクリティカルな脆弱性が5件を含む計18件の脆弱性が報告されました。バッファオーバーフローやコマンドインジェクション、認証回避などにより、攻撃者が特権を取得したり任意のコードを実行したりする可能性があります。
■ 影響範囲
- 対象製品: HPE Networking Instant On AP
- 脆弱性: CVE-2026-76721, CVE-2026-76722 (CVSS 9.8), CVE-2026-76723, CVE-2026-76724, CVE-2026-76725 (CVSS 9.6) 等
■ 対応手順
1. 自社環境で利用している Instant On AP のバージョンを確認してください。
2. HPEが提供する最新のセキュリティアップデートを適用してください。
■ 参考情報
- HPE セキュリティアドバイザリ: HPESBNW05150 rev.1
対応優先度: 高
対応期限: 速やかに
Subject: [Security Advisory] Vulnerabilities in HPE Networking Instant On AP
Dear IT/Security Team,
We are sharing information regarding multiple vulnerabilities identified in HPE Networking Instant On APs.
■ Overview
18 vulnerabilities have been disclosed, including 5 critical ones with CVSS v3.1 scores up to 9.8. These include buffer overflows (CVE-2026-76721, CVE-2026-76722), command injection (CVE-2026-76724), and authentication bypass (CVE-2026-76725), which could allow an attacker to gain privileges or execute arbitrary code.
■ Scope
- Affected Product: HPE Networking Instant On AP
- Key CVEs: CVE-2026-76721, CVE-2026-76722 (9.8), CVE-2026-76723, CVE-2026-76724, CVE-2026-76725 (9.6)
■ Action Plan
1. Identify all HPE Networking Instant On AP devices in the environment.
2. Apply the latest security updates provided by HPE immediately.
■ Reference
- HPE Security Advisory: HPESBNW05150 rev.1
Priority: High
Deadline: Immediate
Dear IT/Security Team,
We are sharing information regarding multiple vulnerabilities identified in HPE Networking Instant On APs.
■ Overview
18 vulnerabilities have been disclosed, including 5 critical ones with CVSS v3.1 scores up to 9.8. These include buffer overflows (CVE-2026-76721, CVE-2026-76722), command injection (CVE-2026-76724), and authentication bypass (CVE-2026-76725), which could allow an attacker to gain privileges or execute arbitrary code.
■ Scope
- Affected Product: HPE Networking Instant On AP
- Key CVEs: CVE-2026-76721, CVE-2026-76722 (9.8), CVE-2026-76723, CVE-2026-76724, CVE-2026-76725 (9.6)
■ Action Plan
1. Identify all HPE Networking Instant On AP devices in the environment.
2. Apply the latest security updates provided by HPE immediately.
■ Reference
- HPE Security Advisory: HPESBNW05150 rev.1
Priority: High
Deadline: Immediate