VYPR
Vypr IntelligenceAI-generatedSep 11, 2026· 7 CVEs

HPE IceWall & ClearPass: Seven High-Severity Flaws Disclosed, Enabling RCE and DoS

HPE disclosed seven vulnerabilities in its IceWall and ClearPass products from Sept 9-11, 2026, with High severity flaws enabling DoS, impersonation, and RCE.

Key findings

  • Seven vulnerabilities disclosed for HPE IceWall and ClearPass products between Sept 9-11, 2026.
  • Flaws include DoS, user impersonation, privilege escalation, and RCE.
  • High severity vulnerabilities (CVSS 7.2-8.8) impact core security functions.
  • Affected products: HPE IceWall Federation Agent/Proxy, ClearPass (CPPM, OnGuard).
  • HPE has released advisories and patches; prompt application is critical.

On September 9-11, 2026, Hewlett Packard Enterprise (HPE) disclosed a batch of seven vulnerabilities affecting its IceWall and ClearPass products. The vulnerabilities, ranging in severity from Medium to High, were disclosed over a two-day period and impact various components including federation agents, proxy servers, and management interfaces. These flaws could lead to denial-of-service conditions, unauthorized access, privilege escalation, and remote code execution.

Several of the vulnerabilities center on HPE's ClearPass Policy Manager (CPPM) and its associated components. CVE-2026-73786, a High severity flaw, allows unauthenticated remote attackers to cause a Denial-of-Service (DoS) by exploiting the web-based management interface. Similarly, CVE-2026-73785, also High severity, affects HPE IceWall Federation Agent and Proxy, enabling remote unauthenticated attackers to cause a DoS.

Further impacting CPPM, CVE-2026-73787 and CVE-2026-73769, both rated High, allow authenticated remote attackers to achieve remote code execution and access directory information, respectively, through the web interface. Successful exploitation of CVE-2026-73787 could lead to arbitrary command execution on the underlying operating system. CVE-2026-73789, a Medium severity vulnerability, permits unauthenticated remote attackers to manipulate guest account settings in CPPM's guest account management services, potentially extending network access beyond policy limits.

Another significant vulnerability, CVE-2026-73784 (High severity), targets HPE IceWall products and could be exploited to tamper with SAML responses, enabling an attacker to impersonate other users. Additionally, CVE-2026-73788, a Medium severity flaw in the ClearPass OnGuard agent, could allow an authenticated remote attacker to elevate their privileges to root on a vulnerable ClearPass OnGuard deployment.

HPE has released advisories and patches for these vulnerabilities. Users are strongly advised to consult the official HPE security bulletins for detailed information on affected product versions and the recommended mitigation steps, including applying the latest security updates to protect their environments from potential exploitation.

This batch of vulnerabilities underscores the importance of timely patching and security updates for critical infrastructure components like identity and access management solutions. Users of HPE IceWall and ClearPass products should prioritize addressing these flaws to prevent potential security breaches, including unauthorized access and system compromise.

The disclosure window for these vulnerabilities spanned from September 9, 2026, to September 11, 2026. The affected products include HPE IceWall Federation Agent and Proxy, and HPE ClearPass products, specifically CPPM and its guest account management services and OnGuard agent.

The vulnerabilities disclosed include:

Users are urged to review HPE's security advisories and apply necessary patches to mitigate these risks.

The batch of vulnerabilities was disclosed between September 9 and September 11, 2026, affecting HPE IceWall and ClearPass products. The issues range from denial-of-service to remote code execution.

HPE has provided security advisories and patches for the identified vulnerabilities. It is crucial for users to apply these updates promptly to secure their systems.

The vulnerabilities include:

Prompt patching is recommended.

AI-written article. Grounded in 7 CVE records listed below.