Skip to content
VulniPulse

HPE Aruba Networking Instant AP / InstantOS Vulnerabilities & Security Advisories

11 advisories tracked · HPE Aruba Networking Security Advisories (PSIRT) via NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published HPE Aruba Networking advisory that VulniPulse classified as Instant AP / InstantOS, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 6 high, 5 medium.

Android app · Google Play

Monitor Aruba CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

HPE Aruba Networking Security Advisories (PSIRT) via NVD

Aruba's PSIRT bulletin portal (arubanetworks.com) is a JavaScript app with no stable public feed, so VulniPulse ingests Aruba's CVEs from NVD. Aruba publishes under the shared HPE CNA (security-alert@hpe.com), which also covers non-networking HPE products — so this feed is filtered to the full HPE Aruba Networking portfolio: ClearPass, AOS-8 mobility controllers, AOS-10 gateways and APs, Instant APs, AOS-CX and legacy AOS-Switch, Aruba Central, Fabric Composer and EdgeConnect/Silver Peak SD-WAN. Each entry links back to the official Aruba/HPE advisory when NVD carries the reference.

Latest Aruba Instant AP / InstantOS advisories

High7.2Aruba

High [CVE-2026-23823] AOS-10: vulnerability in the command line interface of Access Points running AOS-10 could allow an authenticated remote attacker to perform command injection

A vulnerability in the command line interface of Access Points running AOS-10 could allow an authenticated remote attacker to perform command injection. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. NOTE: This vulnerability only impacts Access Points running AOS-10.7.x.x and above. AOS-10.4 AP and AOS-8 Instant software branches are not affected by this vulnerability.

CVE-2026-23823
AOS-10Wireless & ControllersInstantArubaOS
May 12, 2026
High7.2Aruba

High [CVE-2026-23821] AOS-10: vulnerability in the configuration processing logic of Access Points running AOS-10 could allow an authenticated remote attacker to execute system commands under certain pre-existing conditions

A vulnerability in the configuration processing logic of Access Points running AOS-10 could allow an authenticated remote attacker to execute system commands under certain pre-existing conditions. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. Note: Access Points running AOS-8 Instant software are not affected by this vulnerability.

CVE-2026-23821
AOS-10Wireless & ControllersInstantArubaOS
May 12, 2026
High7.2Aruba

High [CVE-2026-23820] AOS-10: vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could allow an authenticated remote attacker to execute system commands in a restricted shell environment

A vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could allow an authenticated remote attacker to execute system commands in a restricted shell environment. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. Affected products named by the advisory: Instant AP.

CVE-2026-23820
AOS-10Instant APWireless & ControllersInstant
May 12, 2026
High8.8Aruba

High [CVE-2026-23819] AOS-10: vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an unauthenticated remote attacker to execute arbitrary JavaScript code in a victim's browser within the same local network

A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an unauthenticated remote attacker to execute arbitrary JavaScript code in a victim's browser within the same local network. Successful exploitation could allow an attacker to compromise user data and potentially manipulate device configuration settings. Affected products named by the advisory: Instant AP.

CVE-2026-23819
AOS-10Instant APWireless & ControllersInstant
May 12, 2026
Medium5.3Aruba

Medium [CVE-2026-23822] AOS-8: vulnerability in the XML handling component of AOS-8 DHCP services could allow an unauthenticated remote attacker to trigger a denial-of-service condition

A vulnerability in the XML handling component of AOS-8 DHCP services could allow an unauthenticated remote attacker to trigger a denial-of-service condition. Successful exploitation could allow an attacker to cause excessive resource consumption upon user interaction, leading to service disruption or reduced availability of the affected system. NOTE: This vulnerability only impacts Access Points running AOS Instant 8.x.x.x Affected product named by the advisory: Instant AP.

CVE-2026-23822
Instant APWireless & ControllersInstantArubaOS
May 12, 2026
Medium6.5Aruba

Medium [CVE-2025-37148] vulnerability in the parsing of ethernet frames in AOS-8 Instant and AOS 10 could

A vulnerability in the parsing of ethernet frames in AOS-8 Instant and AOS 10 could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to potentially disrupt network services and require manual intervention to restore functionality.

CVE-2025-37148
AOS-10Instant APWireless & ControllersInstant
Oct 14, 2025
Medium6.0Aruba

Medium [CVE-2025-27079] vulnerability in the file creation process on the command line interface of AOS-8 Instant and AOS-10 AP could

A vulnerability in the file creation process on the command line interface of AOS-8 Instant and AOS-10 AP could allow an authenticated remote attacker to perform remote code execution (RCE). Successful exploitation could allow an attacker to execute arbitrary operating system commands on the underlying operating system leading to potential system compromise.

CVE-2025-27079
AOS-10Instant APWireless & ControllersInstant
Apr 8, 2025
Medium6.5Aruba

Medium [CVE-2025-27078] vulnerability in a system binary of AOS-8 Instant and AOS-10 AP could

A vulnerability in a system binary of AOS-8 Instant and AOS-10 AP could allow an authenticated remote attacker to inject commands into the underlying operating system while using the CLI. Successful exploitation could lead to complete system compromise.

CVE-2025-27078
AOS-10Instant APWireless & ControllersInstant
Apr 8, 2025
High7.2Aruba

High [CVE-2024-47463] AOS-10: arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface.

An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful exploitation of this vulnerability could allow an authenticated remote attacker to create arbitrary files, which could lead to a remote command execution (RCE) on the underlying operating system.

CVE-2024-47463
AOS-10Instant APWireless & ControllersInstant
Nov 5, 2024
High7.2Aruba

High [CVE-2024-47461] AOS-10: authenticated command injection vulnerability exists in the Instant AOS-8 and AOS-10 command line interface.

An authenticated command injection vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. A successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully compromise the underlying host operating system.

CVE-2024-47461
AOS-10Instant APWireless & ControllersInstant
Nov 5, 2024
Medium6.8Aruba

Medium [CVE-2024-47464] AOS-10: authenticated Path Traversal vulnerability exists in Instant AOS-8 and AOS-10.

An authenticated Path Traversal vulnerability exists in Instant AOS-8 and AOS-10. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location from the command line interface of the underlying operating system, which could lead to a remote unauthorized access to files.

CVE-2024-47464
AOS-10Instant APWireless & ControllersInstant
Nov 5, 2024

← All Aruba advisories