Skip to content
28 CVEs Disclosed for ClearPass Policy Manager, Including Critical RCE Flaws

28 CVEs Disclosed for ClearPass Policy Manager, Including Critical RCE Flaws

First seen 7 Oct 2026, 15:57 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 7, 2026 at 17:29 UTC
  • •28 vulnerabilities disclosed in ClearPass Policy Manager, including 10 critical CVEs.
  • •Critical flaws include unauthenticated RCE and authentication bypass vulnerabilities.
  • •No known exploitation in the wild, but significant risk remains due to unauthenticated access.

HPE's security advisory HPESBNW05158, published on October 6, 2026, reveals 28 vulnerabilities in the ClearPass Policy Manager (CPPM), with 10 classified as critical. Among these, CVE-2026-76750 is a CVSS 9.8 unauthenticated deserialization flaw that allows remote code execution (RCE) via the web interface. Another critical flaw, CVE-2026-76752, permits unauthenticated access to administrative interfaces. The vulnerabilities affect over 5,000 organizations using CPPM for network access control. The advisory states that these vulnerabilities have not been exploited in the wild as of the publication date, but their unauthenticated nature poses a significant risk. The vulnerabilities include SQL injection and authentication bypass flaws, indicating high-value targets for attackers. The North American NAC market is projected to grow significantly, increasing reliance on these platforms. Cisco ISE, a competitor, also recently disclosed critical vulnerabilities, highlighting a trend in infrastructure security risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-06
HPE advisory published
HPE disclosed 28 vulnerabilities in ClearPass Policy Manager, including critical RCE flaws.
Tech.Yahoo
2026-10-06
CVE-2026-79801 published
CVE-2026-79801, an authenticated SQL injection vulnerability with a CVSS of 9.9, was published.
Tech.Yahoo
2026-10-06
CVE-2026-76750 published
CVE-2026-76750, a critical unauthenticated RCE vulnerability, was published.
Tech.Yahoo
2026-10-06
CVE-2026-76754 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-06
CVE-2026-76751 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-06
CVE-2026-76752 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-06
CVE-2026-76753 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-06
CVE-2026-79798 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-06
CVE-2026-79796 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (2)

Following this threat?

Track CVE-2026-76750 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What versions of ClearPass are affected?
The advisory does not specify exact versions, but all versions running ClearPass Policy Manager are at risk.
Have these vulnerabilities been exploited?
As of the advisory's publication, there have been no confirmed exploitations in the wild.
What should organizations do now?
Organizations should monitor for updates from HPE and prepare to apply patches when available.