HPE security advisory HPESBNW05158 rev.1, published October 6, 2026, discloses 28 vulnerabilities within the ClearPass Policy Manager (CPPM). The cluster includes 10 critical, 11 high, and 7 medium-severity CVEs. Among the critical findings are CVE-2026-76750, a CVSS 9.8 unauthenticated deserialization flaw enabling remote code execution (RCE) via the web interface, and CVE-2026-76752, an unauthenticated authentication bypass granting unauthorized administrative access to web-based management and API interfaces.
ClearPass Policy Manager is a primary network access control (NAC) platform, deployed by over 5,000 organizations alongside Cisco ISE. The platform authenticates, authorizes, and enforces access policies across wired, Wi-Fi, and VPN environments. It integrates with more than 150 third-party IT and security systems and utilizes machine learning for device profiling. As a central enforcement point for least-privilege controls, the platform manages the security posture of connected enterprise assets.
The vulnerability set includes CVE-2026-79798, an authenticated SQL injection with a CVSS of 9.9, the highest-rated flaw in the disclosure. Additional critical vulnerabilities include CVE-2026-76751 and CVE-2026-79801, both involving missing integrity verification in agents that lead to unauthenticated RCE. Other critical flaws include CVE-2026-76753, an unauthenticated format string vulnerability leading to RCE; CVE-2026-76754, an unauthenticated SQL injection leading to RCE; and CVE-2026-79796, an unauthenticated authentication bypass. These vulnerabilities span multiple attack vectors, including command injection and path traversal, within the management interface.
These disclosures align with recent patterns in infrastructure security, including the ZITADEL authentication bypass, the Dell CSM credential exposure, and the Loom authentication bypass. Furthermore, the Agent Identity Layer Risk report identified 15 CVEs across four providers within a three-day window. These incidents demonstrate the concentration of risk within centralized management components that serve as the primary arbiter of network trust.
Cisco ISE, the other primary competitor in the NAC space, recently disclosed a cluster of nine critical vulnerabilities. The North American NAC market is projected to reach $12.86 billion by 2034, increasing the reliance on these platforms as central security hubs. The identified vulnerability classes—SQL injection, privilege escalation, and arbitrary file write—are indicators of high-value targets for attackers seeking lateral movement across an enterprise network.
The advisory states that these vulnerabilities have not been exploited in the wild as of the publication date. However, the unauthenticated nature of the critical RCE and authentication bypass flaws presents a significant risk to any organization running affected versions. An unauthenticated attacker gaining administrative control over a NAC platform can manipulate access policies, potentially granting unauthorized users or devices full network access while evading detection. Enterprises running affected versions remain exposed until they apply the necessary updates.
Remediation requires immediate action. HPE has released fixes in CPPM versions 6.14.1 and 6.11.16. Organizations running version 6.12.x or earlier must upgrade to 6.14.1. Given the critical nature of the flaws and the central role ClearPass plays in network security, the window for patching is narrow. Enterprises must prioritize these updates to restore the integrity of their access control layer and mitigate the risk of exploitation of these unauthenticated entry points.
