Skip to content
VulniPulse

HPE Aruba Networking Instant AP / InstantOS Vulnerabilities & Security Advisories

11 advisories tracked · HPE Aruba Networking Security Advisories (PSIRT) via NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published HPE Aruba Networking advisory that VulniPulse classified as Instant AP / InstantOS, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 6 high, 5 medium.

Android app · Google Play

Monitor Aruba CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

HPE Aruba Networking Security Advisories (PSIRT) via NVD

Aruba's PSIRT bulletin portal (arubanetworks.com) is a JavaScript app with no stable public feed, so VulniPulse ingests Aruba's CVEs from NVD. Aruba publishes under the shared HPE CNA (security-alert@hpe.com), which also covers non-networking HPE products — so this feed is filtered to the full HPE Aruba Networking portfolio: ClearPass, AOS-8 mobility controllers, AOS-10 gateways and APs, Instant APs, AOS-CX and legacy AOS-Switch, Aruba Central, Fabric Composer and EdgeConnect/Silver Peak SD-WAN. Each entry links back to the official Aruba/HPE advisory when NVD carries the reference.

Latest Aruba Instant AP / InstantOS advisories

High7.2Aruba Updated

High [CVE-2026-23823] AOS-10: vulnerability in the command line interface of Access Points running AOS-10 could

A vulnerability in the command line interface of Access Points running AOS-10 could allow an authenticated remote attacker to perform command injection. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. NOTE: This vulnerability only impacts Access Points running AOS-10.7.x.x and above. AOS-10.4 AP and AOS-8 Instant software branches are not affected by this vulnerability.

CVE-2026-23823
AOS-10AOS-8 MobilityWireless & ControllersInstant
May 12, 2026
High7.2Aruba Updated

High [CVE-2026-23821] AOS-10: vulnerability in the configuration processing logic of Access Points running AOS-10 could

A vulnerability in the configuration processing logic of Access Points running AOS-10 could allow an authenticated remote attacker to execute system commands under certain pre-existing conditions. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. Note: Access Points running AOS-8 Instant software are not affected by this vulnerability.

CVE-2026-23821
AOS-10AOS-8 MobilityWireless & ControllersInstant
May 12, 2026
High7.2Aruba

High [CVE-2026-23820] AOS-10: vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could

A vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could allow an authenticated remote attacker to execute system commands in a restricted shell environment. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.

CVE-2026-23820
Wireless & ControllersInstantArubaOS
May 12, 2026
High8.8Aruba Updated

High [CVE-2026-23819] AOS-10: vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could

A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an unauthenticated remote attacker to execute arbitrary JavaScript code in a victim's browser within the same local network. Successful exploitation could allow an attacker to compromise user data and potentially manipulate device configuration settings.

CVE-2026-23819
Wireless & ControllersInstantArubaOS
May 12, 2026
High7.2Aruba

High [CVE-2024-47463] AOS-10: arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface.

An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful exploitation of this vulnerability could allow an authenticated remote attacker to create arbitrary files, which could lead to a remote command execution (RCE) on the underlying operating system.

CVE-2024-47463
Wireless & ControllersInstantArubaOS
Nov 5, 2024
High7.2Aruba

High [CVE-2024-47461] AOS-10: authenticated command injection vulnerability exists in the Instant AOS-8 and AOS-10 command line interface.

An authenticated command injection vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. A successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully compromise the underlying host operating system.

CVE-2024-47461
Wireless & ControllersInstantArubaOS
Nov 5, 2024

← All Aruba advisories