Database/Control plane, storage & DevOps

HPE OneView (unauthenticated remote code execution): Unauthenticated remote code execution on OneView with scope change
Impact
Unauthenticated remote code execution on OneView with scope change - a perfect-10 finding. OneView is HPE's fleet management plane: it holds iLO credentials, drives firmware deployment and owns server profiles, so RCE there is effectively root on every managed server. A public Metasploit module exists.
Who can reach it
Anyone who can reach the OneView web interface. No credentials.
What to do
Patch OneView immediately per HPESBGN04985 - this is the single highest-priority item in this sweep. Appliance update with a service restart. Assume compromise if OneView has been network-reachable and unpatched: rotate every iLO and service-account credential it holds, and review deployed firmware for tampering.
References
Related entries
- Ivanti Sentry: OS command injectionCVE-2026-10520 · Ivanti SentryCritical
- Cisco Secure Firewall Management Center: unauthenticated HTTP request yields root on the applianceCVE-2026-20079 · Cisco Secure Firewall Management Center (web interface)Critical
- Kestra: suffix-match auth bypass on /configs gives unauthenticated workflow execution as rootCVE-2026-49869 · Kestra AuthenticationFilter (suffix match on the /configs path whitelist)Critical
- Linux crypto driver for Marvell OCTEON TX: The scatter-gather cleanup path in the Marvell OCTEON TX crypto driver usesCVE-2026-74280 · Linux crypto driver for Marvell OCTEON TXCritical
- Linux VXLAN driver (neighbour hardware address read in route_shortcircuit): `route_shortcircuit()` reads a neighbour'sCVE-2026-74475 · Linux VXLAN driver (neighbour hardware address read in route_shortcircuit)Critical
- Cisco ISE: unauthenticated API endpoint allows full authentication bypass on the applianceCVE-2026-76460 · Cisco Identity Services Engine (unauthenticated API endpoint)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.