HPE AutoPass Vulnerability Let Attackers Bypass Authentication Remotely
ID: 1d47d964-cf6c-5391-93b7-700992f7c0f2
STIX ID: report--1d47d964-cf6c-5391-93b7-700992f7c0f2
Feed Name: cybersecurityNews.com
Threat Score
HPE has published an advisory for CVE-2026-23600, an authentication-bypass vulnerability in AutoPass License Server (APLS) prior to 9.19 that can be exploited remotely without privileges or user interaction (CVSS 7.3). HPE recommends upgrading to a fixed release and temporary mitigations such as restricting network exposure to trusted admin subnets/VPNs, auditing admin access, monitoring for suspicious activity, and applying host OS patches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
