HPE has published a critical bulletin for Integrated Lights-Out 7. CVE-2026-79820 is a remote user-validation failure scored 9.0. It is not listed as exploited in the wild.
What happened
The National Vulnerability Database published the record on 5 October 2026. HPE's bulletin, HPESBHF05163, describes a user validation failure in iLO 7 when COM is in use. The score is critical: network reachable, no privileges required, and high impact on confidentiality, integrity, and availability. Attack complexity is rated high, so this is not a one-packet takeover, but a successful bypass would reach the out-of-band management plane.
iLO can power-cycle a server, mount virtual media, and open a remote console. A flaw here is an admin path, not a side feature.
Who is affected
HPE lists iLO 7. The NVD affected-product entry names firmware 1.25.00. Older iLO generations are not named in this CVE.
- HPE ProLiant and compute servers that ship with iLO 7
- Management networks where iLO is reachable beyond a dedicated admin VLAN
- Hosts where firmware 1.25.00 is still installed
What to do now
Install the fix in HPE bulletin HPESBHF05163, and keep iLO off the public internet. Confirm the interface is only reachable from the management network, and review iLO accounts for logins you did not issue.
Source: NVD and HPE bulletin HPESBHF05163.
Also on the blog
- Exchange CVE-2026-96940: signed-in users can read other mailboxes
- ClickFix cache smuggling bypasses the Windows Run character limit
- Cling botnet hides operator commands inside STUN traffic
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.