Hewlett Packard Enterprise released ALE 5.1.0.0 to fix ten vulnerabilities in HPE Networking Analytics and Location Engine (ALE) 5.0.0.0 and earlier. The most severe, CVE-2026-76708 (hard-coded default credentials) and CVE-2026-76709 (privileged arbitrary file write), are remotely exploitable without authentication, carry CVSS 9.8 scores, and could enable full appliance compromise.
The ALE advisory also addresses information disclosure, data injection, root-level filesystem and command-execution exposure, man-in-the-middle risk, denial of service, and password-hash disclosure. HPE reported no known public exploit code or active exploitation, but administrators should upgrade immediately and restrict or segment access to ALE management interfaces; a related HPE advisory also identifies a remote denial-of-service vulnerability in Telco Service Orchestrator 5.6.0 and earlier.

Map this exposure pattern across your cloud, code, and identities.
2 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security published advisory AV26-951 covering HPE ALE vulnerabilities and a remote denial-of-service vulnerability affecting HPE Telco Service Orchestrator 5.6.0 and earlier. It directed users and administrators to review HPE bulletins HPESBNW05137 and HPESBNW05151 and apply available updates.
HPE issued advisory HPESBNW05137 revision 1 for multiple vulnerabilities in HPE Networking Analytics and Location Engine (ALE) 5.0.0.0 and earlier, including two CVSS 9.8 unauthenticated remote flaws (CVE-2026-76708 and CVE-2026-76709). The company released ALE 5.1.0.0 to remediate the flaws and said it was unaware of public exploit code or active exploitation at publication.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.