HPE iLO 7 CVE-2026-79820 scores 9.0 on user validation
HPE iLO 7 remote user validation failure

HPE iLO 7 CVE-2026-79820 scores 9.0 on user validation

HPE has published a critical bulletin for Integrated Lights-Out 7. CVE-2026-79820 is a remote user-validation failure scored 9.0. It is not listed as exploited in the wild.

What happened

The National Vulnerability Database published the record on 5 October 2026. HPE's bulletin, HPESBHF05163, describes a user validation failure in iLO 7 when COM is in use. The score is critical: network reachable, no privileges required, and high impact on confidentiality, integrity, and availability. Attack complexity is rated high, so this is not a one-packet takeover, but a successful bypass would reach the out-of-band management plane.

iLO can power-cycle a server, mount virtual media, and open a remote console. A flaw here is an admin path, not a side feature.

Who is affected

HPE lists iLO 7. The NVD affected-product entry names firmware 1.25.00. Older iLO generations are not named in this CVE.

  • HPE ProLiant and compute servers that ship with iLO 7
  • Management networks where iLO is reachable beyond a dedicated admin VLAN
  • Hosts where firmware 1.25.00 is still installed

What to do now

Install the fix in HPE bulletin HPESBHF05163, and keep iLO off the public internet. Confirm the interface is only reachable from the management network, and review iLO accounts for logins you did not issue.

Source: NVD and HPE bulletin HPESBHF05163.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

ClickFix cache smuggling bypasses the Windows Run character limit
ClickFix payload staged in the browser cache