HPE security advisory (AV26-909)

Published September 10, 2026

HPE's ClearPass and IceWall security tools have flaws that let attackers crash them or hijack user sessions. This affects Canadian government and business networks.

Severity
Not scoredNo CVSS score recorded
Fix
Fixed in 6.11.15
Exploited
Not confirmedNo confirmation recorded

How it works

  • Attackers send specially crafted requests to ClearPass Policy Manager or IceWall.
  • These requests trick the software into misreading its own data, causing crashes or session hijacking.
  • The flaws let attackers take over user accounts or stop the tools from working.

What to do

Check if you use HPE ClearPass Policy Manager or IceWall. If you're running ClearPass 6.11.14 or earlier, or 6.12.8 or earlier, you're affected. For IceWall, any version may be vulnerable. Review your installed versions in the product's admin console or contact HPE support for help.

Update ClearPass Policy Manager to 6.11.15 or 6.12.9. For IceWall, apply the latest patch from HPE's advisory. Check the HPE support portal for updates or contact HPE support if unsure.

Technical details

HPE disclosed multiple vulnerabilities in ClearPass Policy Manager (CPPM) and HPE IceWall products, affecting versions up to 6.11.14, 6.12.8, and unspecified IceWall models. These flaws allow attackers to bypass authentication controls, execute unauthorized commands, or escalate privileges, potentially gaining full system access. The vulnerabilities were assigned the internal identifier NEWS-f31eb99340a424b93d and were reported to HPE on September 9, 2026. Affected users are urged to apply available patches or updates to mitigate risk.