HPE issued security advisories for vulnerabilities affecting two telecom orchestration products: HPE Telco Service Orchestrator and HPE Telco Network Function Virtualization Orchestrator. The first bulletin, HPESBNW05031 rev.1, covers multiple vulnerabilities in HPE Telco Service Orchestrator versions prior to v5.5.1, while a separate advisory addresses a critical flaw in HPE Telco Network Function Virtualization Orchestrator affecting v7.5.0 and earlier.
The critical issue in HPE Telco Network Function Virtualization Orchestrator was tied to improper input validation in the Undertow HTTP Server Core. The Canadian Centre for Cyber Security urged organizations using either product to review HPE’s security bulletins and apply the required updates to remediate the exposed versions.

See the actors and campaigns active against you right now.
4 events from the most recent confirmed update back to the earliest known activity.
HPE published security advisory HPESBNW05047 rev.1 for multiple vulnerabilities in HPE Telco Service Orchestrator Software. The advisory represents a new vendor disclosure affecting the product beyond the earlier March 2026 notice.
HPE published a security advisory for a critical improper input validation vulnerability in the Undertow HTTP Server Core affecting HPE Telco Network Function Virtualization Orchestrator. The issue affected version 7.5.0 and earlier, and administrators were urged to review and apply HPE's updates.
HPE published security advisory HPESBNW05031 rev.1 addressing multiple vulnerabilities in HPE Telco Service Orchestrator. The affected versions were those prior to v5.5.1, and users were advised to apply the updates.
HPE issued security advisory HPESBNW05078 rev.1 for HPE Telco Service Orchestrator Software covering a privilege-escalation to filesystem read-access issue via Automatic ConfigProvider. This is a separate vendor disclosure from the later March and April 2026 Telco Service Orchestrator advisories.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
5 references tracked. Mallory keeps watching after this page renders.
cyber.gc.ca
Open sourcesupport.hpe.com
Open sourcecyber.gc.ca
Open sourcecyber.gc.ca
Open sourcesupport.hpe.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.