Skip to content
VulniPulse

HPE Aruba Networking AOS-8 Mobility Controllers Vulnerabilities & Security Advisories

38 advisories tracked · HPE Aruba Networking Security Advisories (PSIRT) via NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published HPE Aruba Networking advisory that VulniPulse classified as AOS-8 Mobility Controllers, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 24 high, 13 medium, 1 low.

Android app · Google Play

Monitor Aruba CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

HPE Aruba Networking Security Advisories (PSIRT) via NVD

Aruba's PSIRT bulletin portal (arubanetworks.com) is a JavaScript app with no stable public feed, so VulniPulse ingests Aruba's CVEs from NVD. Aruba publishes under the shared HPE CNA (security-alert@hpe.com), which also covers non-networking HPE products — so this feed is filtered to the full HPE Aruba Networking portfolio: ClearPass, AOS-8 mobility controllers, AOS-10 gateways and APs, Instant APs, AOS-CX and legacy AOS-Switch, Aruba Central, Fabric Composer and EdgeConnect/Silver Peak SD-WAN. Each entry links back to the official Aruba/HPE advisory when NVD carries the reference.

Latest Aruba AOS-8 Mobility Controllers advisories

High7.2Aruba

High [CVE-2026-44871] AOS-10: Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS-8 and AOS-10 Operating Systems

Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.

CVE-2026-44871
AOS-10AOS-8 MobilityWireless & ControllersArubaOS
May 12, 2026
High7.2Aruba

High [CVE-2026-44872] AOS-10: command injection vulnerability exists in the web-based management interface of AOS-8 and AOS-10 Operating Systems

A command injection vulnerability exists in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to place arbitrary files on the underlying filesystem of the affected device. Affected products named by the advisory: AOS-8 Mobility.

CVE-2026-44872
AOS-10AOS-8 MobilityWireless & ControllersArubaOS
May 12, 2026
High7.2Aruba

High [CVE-2026-44870] AOS-10: Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS-8 and AOS-10 Operating Systems

Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system. Affected products named by the advisory: AOS-8 Mobility.

CVE-2026-44870
AOS-10AOS-8 MobilityWireless & ControllersArubaOS
May 12, 2026
High7.2Aruba

High [CVE-2026-44869] AOS-10: Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems

Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system. Affected products named by the advisory: AOS-8 Mobility.

CVE-2026-44869
AOS-10AOS-8 MobilityWireless & ControllersArubaOS
May 12, 2026
High7.2Aruba

High [CVE-2026-44864] AOS-10: SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol

SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative privileges could exploit these vulnerabilities by injecting crafted input into parameters that are passed unsanitized to backend database queries. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system. Affected products named by the advisory: AOS-8 Mobility.

CVE-2026-44864
AOS-10AOS-8 MobilityWireless & ControllersArubaOS
May 12, 2026
High7.2Aruba

High [CVE-2026-44859] AOS-10: Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems

Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authenticated attacker with administrative privileges could exploit these vulnerabilities by sending specially crafted requests to the affected services. Successful exploitation could allow the attacker to execute arbitrary code with elevated privileges on the underlying operating system. Affected products named by the advisory: AOS-8 Mobility.

CVE-2026-44859
AOS-10AOS-8 MobilityWireless & ControllersArubaOS
May 12, 2026
High7.2Aruba

High [CVE-2026-44854] AOS-10: Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems

Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to upload arbitrary files to the underlying operating system, potentially leading to remote code execution as a privileged user. Affected products named by the advisory: AOS-8 Mobility.

CVE-2026-44854
AOS-10AOS-8 MobilityWireless & ControllersArubaOS
May 12, 2026
High7.2Aruba

High [CVE-2026-44852] AOS-10: authenticated remote code execution vulnerability exists in the AOS-8 and AOS-10 web-based management interface

An authenticated remote code execution vulnerability exists in the AOS-8 and AOS-10 web-based management interface. A vulnerability in the certificate download functionality could allow an authenticated remote attacker to overwrite arbitrary files on the underlying operating system by exploiting improper input validation in the file path parameter. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system as a privileged user. Affected products named by the advisory: AOS-8 Mobility.

CVE-2026-44852
AOS-10AOS-8 MobilityWireless & ControllersArubaOS
May 12, 2026
High7.5Aruba

High [CVE-2026-23827] AOS-10: heap-based buffer overflow vulnerability exists in a Network management service of AOS-8 and AOS-10 that could allow an unauthenticated remote attacker to achieve remote code execution

A heap-based buffer overflow vulnerability exists in a Network management service of AOS-8 and AOS-10 that could allow an unauthenticated remote attacker to achieve remote code execution. Successful exploitation could allow an unauthenticated attacker to execute arbitrary code as a privileged user on the underlying operating system, potentially leading to a system compromise. Exploitation may also result in a denial-of-service (DoS) condition affecting the impacted system process. Affected products named by the advisory: AOS-8 Mobility.

CVE-2026-23827
AOS-10AOS-8 MobilityWireless & ControllersArubaOS
May 12, 2026
High7.5Aruba

High [CVE-2026-23826] AOS-8: vulnerability in a network management service of AOS-8 Operating System could allow an unauthenticated remote attacker to exploit this vulnerability by sending specially crafted network packets to the affected device, potentially resulting in a denial-of-service condition

A vulnerability in a network management service of AOS-8 Operating System could allow an unauthenticated remote attacker to exploit this vulnerability by sending specially crafted network packets to the affected device, potentially resulting in a denial-of-service condition. Successful exploitation could cause the affected service process to terminate unexpectedly, disrupting normal device operations. Affected product named by the advisory: AOS-8 Mobility.

CVE-2026-23826
AOS-8 MobilityWireless & ControllersArubaOS
May 12, 2026
Medium5.4Aruba

Medium [CVE-2026-44873] AOS-8: session management vulnerability in AOS-8 allows previously authenticated users to retain network access after their accounts are administratively disabled

A session management vulnerability in AOS-8 allows previously authenticated users to retain network access after their accounts are administratively disabled. Existing sessions are not invalidated when credentials are revoked, enabling continued access until session expiration. An attacker with compromised credentials could exploit this behavior to maintain unauthorized access even after the account has been disabled. Affected product named by the advisory: AOS-8 Mobility.

CVE-2026-44873
AOS-8 MobilityWireless & ControllersArubaOS
May 12, 2026
High7.2Aruba

High [CVE-2025-37175] Arbitrary file upload vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or…

Arbitrary file upload vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor to upload arbitrary files as a privilege user and execute arbitrary commands on the underlying operating system.

CVE-2025-37175
AOS-10AOS-8 MobilityWireless & ControllersMobility Conductor
Jan 13, 2026
High7.2Aruba

High [CVE-2025-37174] AOS-10: Authenticated arbitrary file write vulnerability exists in the web-based management interface of mobility conductors running…

Authenticated arbitrary file write vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor to create or modify arbitrary files and execute arbitrary commands as a privileged user on the underlying operating system.

CVE-2025-37174
AOS-10AOS-8 MobilityWireless & ControllersMobility Conductor
Jan 13, 2026
High7.2Aruba

High [CVE-2025-37173] AOS-10: improper input handling vulnerability exists in the web-based management interface of mobility conductors running either…

An improper input handling vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor with valid credentials to trigger unintended behavior on the affected system.

CVE-2025-37173
AOS-10AOS-8 MobilityWireless & ControllersMobility Conductor
Jan 13, 2026
High7.2Aruba

High [CVE-2025-37172] Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8…

Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system.

CVE-2025-37172
AOS-8 MobilityWireless & ControllersMobility ConductorArubaOS
Jan 13, 2026
High8.2Aruba

High [CVE-2025-37168] Arbitrary file deletion vulnerability have been identified in a system function of mobility conductors running AOS-8 operating…

Arbitrary file deletion vulnerability have been identified in a system function of mobility conductors running AOS-8 operating system. Successful exploitation of this vulnerability could allow an unauthenticated remote malicious actor to delete arbitrary files within the affected system and potentially result in denial-of-service conditions on affected devices.

CVE-2025-37168
AOS-8 MobilityWireless & ControllersMobility ConductorArubaOS
Jan 13, 2026
Medium6.5Aruba

Medium [CVE-2025-37177] AOS-10: arbitrary file deletion vulnerability has been identified in the command-line interface of mobility conductors running either…

An arbitrary file deletion vulnerability has been identified in the command-line interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation of this vulnerability could allow an authenticated remote malicious actor to delete arbitrary files within the affected system.

CVE-2025-37177
AOS-10AOS-8 MobilityWireless & ControllersMobility Conductor
Jan 13, 2026
Medium6.5Aruba

Medium [CVE-2025-37176] command injection vulnerability in AOS-8

A command injection vulnerability in AOS-8 allows an authenticated privileged user to alter a package header to inject shell commands, potentially affecting the execution of internal operations. Successful exploit could allow an authenticated malicious actor to execute commands with the privileges of the impacted mechanism.

CVE-2025-37176
AOS-8 MobilityWireless & ControllersArubaOS
Jan 13, 2026
High7.2Aruba

High [CVE-2025-37134] authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating…

An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system.

CVE-2025-37134
AOS-8 MobilityWireless & ControllersMobility ConductorArubaOS
Oct 14, 2025
High7.2Aruba

High [CVE-2025-37132] arbitrary file write vulnerability exists in the web-based management interface of both the AOS-10 GW and AOS-8…

An arbitrary file write vulnerability exists in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to upload arbitrary files and execute arbitrary commands on the underlying operating system.

CVE-2025-37132
AOS-10AOS-8 MobilityWireless & ControllersMobility Conductor
Oct 14, 2025

← All Aruba advisories