Hewlett Packard Enterprise issued security bulletins for multiple vulnerabilities affecting HPE Networking Instant On access points, HPE Telco Service Orchestrator, HPE Unified OSS Console, Compute Scale-up Server 3200 and 3250 platforms, and HPE Superdome Flex systems. The disclosures include unspecified flaws as well as vulnerabilities enabling remote RMC file modification and remote command execution on specified enterprise-server platforms.
Administrators should identify affected HPE assets, review the applicable product security bulletins, and upgrade to the listed fixed versions or later where available. Organizations should prioritize remediation of internet-accessible and operationally critical server-management systems, given the potential impact of remote command execution and unauthorized file modification.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
The Canadian Cyber Centre published advisory AV26-982 covering the HPE product vulnerabilities and recommending that administrators review HPE's bulletins and apply applicable updates.
HPE published security bulletins for multiple vulnerabilities affecting Networking Instant On APs, Telco Service Orchestrator, Unified OSS Console, Compute Scale-up Server 3200 and 3250, and Superdome Flex systems. The disclosures included remote RMC file-modification and remote command-execution issues affecting specified Compute Scale-up and Superdome platforms.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.