Tech.Yahoo 28 CVEs Disclosed for ClearPass Policy Manager, Including Critical RCE Flaws
Article Content
- •28 vulnerabilities disclosed in ClearPass Policy Manager, including 10 critical CVEs.
- •Critical flaws include unauthenticated RCE and authentication bypass vulnerabilities.
- •No known exploitation in the wild, but significant risk remains due to unauthenticated access.
HPE's security advisory HPESBNW05158, published on October 6, 2026, reveals 28 vulnerabilities in the ClearPass Policy Manager (CPPM), with 10 classified as critical. Among these, CVE-2026-76750 is a CVSS 9.8 unauthenticated deserialization flaw that allows remote code execution (RCE) via the web interface. Another critical flaw, CVE-2026-76752, permits unauthenticated access to administrative interfaces. The vulnerabilities affect over 5,000 organizations using CPPM for network access control. The advisory states that these vulnerabilities have not been exploited in the wild as of the publication date, but their unauthenticated nature poses a significant risk. The vulnerabilities include SQL injection and authentication bypass flaws, indicating high-value targets for attackers. The North American NAC market is projected to grow significantly, increasing reliance on these platforms. Cisco ISE, a competitor, also recently disclosed critical vulnerabilities, highlighting a trend in infrastructure security risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-76750 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What versions of ClearPass are affected?
Have these vulnerabilities been exploited?
What should organizations do now?
Continue Reading
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…