Market Pulse · edition of Oct 2, 2026
What moved this month in hardware pricing, vendor deals and security, and what it means for you.
Hardware pricing and supply, vendor deals and licensing changes, security alerts and funding signals shaping IT and security operations for businesses and public organizations alike, read from the practitioner's side of the table.
Networking
Juniper's partner program folds into HPE's
HPE closed its Juniper acquisition in July 2025. From Nov 1, Juniper partners move to HPE Partner Ready Vantage. What it means: if your firewalls or switches are Juniper, confirm your reseller's standing and support path before your next renewal or E-Rate bid.
Security
CISA adds an actively exploited FortiMail flaw to its KEV catalog
CISA added a path-traversal vulnerability in Fortinet FortiMail to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation. The alert text did not list a separate remediation date and points agencies to its directive on prioritizing flaws on internet-facing systems. What it means: if you filter email with FortiMail, check the vendor advisory for your version, patch promptly and confirm the admin interface is not exposed to the internet. Source: CISA
Networking · AI
HPE raises its networking outlook and lands a $1.2 billion AI rack order
HPE lifted its fiscal 2027 networking growth forecast to the high teens to low 20s percent, up from 14% to 17%, and raised its Juniper synergy target to $800 million a year. It also won a $1.2 billion order from cloud provider Vultr for AMD-based AI racks that include Juniper switches. What it means: HPE is betting heavily on networking, and large AI orders compete with everyone else for the same components. If you plan HPE, Juniper or Aruba purchases, ask for a firm delivery date and how long the quote stays valid. Source: Yahoo Finance
Observability · AI
Dynatrace closes its Arize acquisition
Dynatrace completed the purchase of Arize, an AI tracing and evaluation vendor, to cover AI applications from development through production. Arize AX and Dynatrace stay available as separate products, the open-source Phoenix project continues, and no pricing or licensing changes were announced. What it means: if you are putting AI agents or copilots into service, ask your observability vendor how model calls, cost and quality will be monitored, and watch for packaging changes at your next renewal. Source: Dynatrace
Hardware · Pricing
TrendForce: memory contract prices keep climbing in the fourth quarter
TrendForce expects conventional DRAM contract prices to rise 10% to 15% and NAND flash 15% to 20% quarter over quarter in 4Q26. Enterprise SSD is the one category where increases should speed up, while client SSD increases are being held back. Server DRAM stays tight. What it means: quotes for memory-heavy servers, virtualization hosts and storage are likely to move up again and expire sooner. Lock in pricing on planned refreshes now, and spend your flexibility on laptops and desktops, where increases are milder. Source: TrendForce
Security
CISA flags exploited SharePoint and Mikrotik RouterOS flaws
CISA added two more actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: a code-injection flaw in on-premises Microsoft SharePoint Server that lets a logged-in user run arbitrary code, and an SSH authentication-bypass bug in Mikrotik RouterOS that lets an unauthenticated attacker open a session and alter device files. Federal agencies must remediate by Sep 28. What it means: cities and districts still running SharePoint on premises, or RouterOS-based routers in budget network builds, should patch now and confirm SSH management isn't reachable from untrusted networks. Source: CISA
E-Rate
FCC's E-Rate overhaul review hits its first deadline
The FCC's proceeding reviewing E-Rate's scope, size and even a possible narrowing over screen-time concerns closes for initial comments Sep 26, with reply comments due Nov 12. It's a separate, more consequential policy track than the routine fall filing deadlines. What it means: district and library technology leaders, and the consultants who support them, should read the docket and weigh in by Nov 12; the outcome could reshape which devices and services qualify for E-Rate discounts. Source: Federal Register
ServiceNow · Security
ServiceNow patches two max-severity AI Platform flaws
ServiceNow's Sep 24 advisory fixes five AI Platform vulnerabilities, including an unauthenticated SQL injection and a missing-authorization bug, each rated a maximum CVSS 10.0, plus three more high-severity access-control issues. ServiceNow reports no evidence of exploitation. What it means: if you run ServiceNow for ITSM, HR or procurement, confirm with your admin team or MSP that the patch is applied, especially on any instance reachable from the internet. Source: Cyber Security News
Wireless
IDC: enterprise Wi-Fi grows 23% as Wi-Fi 7 passes half of access-point revenue
IDC put 2Q26 worldwide enterprise WLAN revenue at $3.2 billion, up 23.2% from a year earlier. Wi-Fi 7 made up 53% of enterprise access-point revenue. Cisco held 39% of the market, HPE/Juniper 17.2% and Ubiquiti 12.8%. IDC says industry-wide memory shortages are stretching lead times and raising prices. What it means: if a Wi-Fi refresh is in your plan or your E-Rate request, expect longer waits and firmer prices on Wi-Fi 7 access points, and decide whether to order early or hold off. Source: IDC
Hardware · Pricing
Dell'Oro: campus switch prices up 19% as memory shortages bite
Dell'Oro reports average selling prices for campus switches rose 19% year over year in 2Q26, and every vendor outside China raised them. AI-driven component shortages limited availability, and Dell'Oro expects memory scarcity to last through 2027. Cisco, Arista, Ubiquiti and Extreme gained share. What it means: budget switch refreshes with a price cushion and a longer lead time than last year, and ask your reseller how long a quoted price will hold. Source: Dell'Oro Group