CVE-2026-76752

LOWCVSS 9.8 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Authentication bypass vulnerabilities exist in the web-based management and API interfaces of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an unauthenticated remote attacker to circumvent existing authentication controls and gain administrative access to the affected system.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked at 3 mentions on most recent observed day (2026-10-08)
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-10-07: 1Mentions · 2026-10-08: 310-0710-08
Referenced assets2 URLs
Full discourse4 posts
  • CCB Alert@CCBalert

    Warning: Critical vulnerabilities in #HPE ClearPass Policy Manager allow unauthenticated attackers to execute arbitrary code or gain admin access. #CVE-2026-76750 #CVE-2026-76752 #CVE-2026-76753 CVSS(3.1): 9.8. Read the advisory https://ccb.belgium.be/advisories/warning-multiple-critical-vulnerabilities-hpe-networking-clearpass-policy-manager-can-be and #Patch #Patch #Patch

    02012181
    7.3K followersView on X
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs

    CVE-2026-76752 affects HPE Aruba ClearPass Policy Manager. Unauthenticated authentication bypass can allow attackers to alter access policies, expose credentials or disrupt network controls. #CyberSecurity #NetworkSecurity #AccessControl

    0000018
    63 followersView on X
  • Atlas Threat Monitoring@ThreatAtlas

    Unpatched vulnerabilities don't stay hidden on our atlas. #CVE CRITICAL VULNERABILITY DETECTED CVE ID → CVE-2026-76752 Vendor → Unknown Severity → Critical — CVSS 9.8 Product → Unknown Date → 2026-10-06 A critical vulnerability (Improper Authentication) has been disclosed affecting Unknown. Patch immediately. Powered by @Brandefense #ThreatIntel #CyberSecurity #CVE #Unknown

    0000040
    451 followersView on X
  • The Hacker Wire@TheHackerWire

    🚨 CVE-2026-76752 (CVSS 9.8 Critical) An authentication bypass in HPE ClearPass Policy Manager web and API interfaces permits unauthenticated remote attackers to obtain administrative control. https://www.thehackerwire.com/vulnerability/CVE-2026-76752/ https://t.co/El6VWKJOvd

    0000041
    176 followersView on X

Explore more