Loading...
Loading...
HPE MR Storage Administrator (MRSA) uses NGINX version 1.28 to facilitate HPE MR controller management via a web browser. This version of NGINX server used is affected by the following Common Vulnerabilities and Exposures (CVEs):CVE-2026-9256CVE-2026-42945CVE-2026-42946CVE-2026-40701CVE-2026-42934CVE-2026-42533CVE-2026-60005CVE-2026-55723The underlying NGINX version is technically within the affected baseline, but the MRSA application configuration naturally immunizes the system from the active exploit paths. Furthermore, strict local-only network restrictions prevent any external internet-facing threats.Broadcom states that they bind NGINX strictly to local loopback interfaces (127.0.0.1 and [::1]). This means HPE MRSA does not listen on any public network interfaces, blocking all external automated scanners or internet threat actors.The table below outlines Broadcom's assessment of each of the CVEs:CVESeverityComponentRiskBroadcom Evaluation with respect to MRSACVE-2026-9256HighNGINX CoreInert/SafeRequires nested regex capture parameters. Completely absent from our configuration.CVE-2026-42945Medium/HighNGINX CoreInert/SafeRequires rewrite module triggers. Our configuration contains zero rewrite rules, neutralizing the threat.CVE-2026-42946High/CriticalNGINX CoreInert/SafeRequires SCGI/uWSGI upstream configurations. Our setup safely uses FastCGI exclusively.CVE-2026-40701MediumNGINX CoreInert/SafeInitiates via specific client certificate validation and Online Certificate Status Protocol (OCSP) features. These elements are completely inactive in our file.CVE-2026-42934MediumNGINX CoreLow RiskRelies on internal upstream buffer misalignments. Handled securely via our localized internal proxies.CVE-2026-42533CriticalNGINX CoreInert/SafeExposure requires specific configurations. HPE MRSA's nginx.conf file does not utilize the map or slice directives, so is not exposed.CVE-2026-60005High/CriticalNGINX CoreInert/SafeExposure requires specific configurations. MRSA's nginx.conf does not utilize the map or slice directives, so is not exposed.CVE-2026-55723HighNGINX CoreInert/SafeThis issue exclusively impacts the NGINX Ingress Controller in Kubernetes environments. Aa a standalone NGINX server, this does not apply to HPE MRSA.
HPE MR Storage Administrator running on both Microsoft Windows Server and Linux.HPE MegaRAID Storage Administrator for Windows 64-bit (HPE MRSA for MR Controllers), version 8.16.13.0 and earlierHPE MegaRAID Storage Administrator for RHEL10 (HPE MRSA for MR Controllers), version 8.16.13.0 and earlierHPE MegaRAID Storage Administrator for RHEL9 ,SLES15 and SLES16 (HPE MRSA for MR Controllers), version 8.16.13.0 and earlierHPE MegaRAID Storage Administrator for Ubuntu (HPE MRSA for MR Controllers), version 8.16.13.0 and earlier
Broadcom has reviewed CVE-2026-9256, CVE-2026-42945, CVE-2026-42946, CVE-2026-40701, CVE-2026-42533, CVE-2026-60005, and CVE-2026-55723, and they have confirmed that the HPE MRSA application is not affected and that CVE-2026-42934 presents Low Risk.See thenginx security advisoriespage for more information.Disclaimer: One or more of the links above will take you outside the HPE website. HPE is not responsible for content outside of its domain.Revision HistoryDocument VersionRelease DateDetails2August 17, 2026Updated the Title, updated the first paragraph and added three (3) CVEs to the bullet list in the Description section, updated the table in the Description with the added CVEs, and updated the first paragraph in the Resolution section.1July 28, 2026Original Document Release
Operating Systems Affected:Microsoft Windows Server 2019, Microsoft Windows Server 2022, Microsoft Windows Server 2025, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0, Red Hat Enterprise Linux 10.1, Red Hat Enterprise Linux 10.2, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.0, Red Hat Enterprise Linux 9.1, Red Hat Enterprise Linux 9.2, Red Hat Enterprise Linux 9.3, Red Hat Enterprise Linux 9.4, Red Hat Enterprise Linux 9.5, Red Hat Enterprise Linux 9.8, SUSE Linux Enterprise Server 15, SUSE Linux Enterprise Server 16, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS
Click on a version to see all relevant bugs
Hewlett Packard Enterprise Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.