Skip to content
VulniPulse

HPE Aruba Networking Instant AP / InstantOS Vulnerabilities & Security Advisories

29 advisories tracked · HPE Aruba Networking Security Advisories (PSIRT) via NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published HPE Aruba Networking advisory that VulniPulse classified as Instant AP / InstantOS, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 5 critical, 9 high, 12 medium, 3 low.

Android app · Google Play

Monitor Aruba CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

HPE Aruba Networking Security Advisories (PSIRT) via NVD

Aruba's PSIRT bulletin portal (arubanetworks.com) is a JavaScript app with no stable public feed, so VulniPulse ingests Aruba's CVEs from NVD. Aruba publishes under the shared HPE CNA (security-alert@hpe.com), which also covers non-networking HPE products — so this feed is filtered to the full HPE Aruba Networking portfolio: ClearPass, AOS-8 mobility controllers, AOS-10 gateways and APs, Instant APs, AOS-CX and legacy AOS-Switch, Aruba Central, Fabric Composer and EdgeConnect/Silver Peak SD-WAN. Each entry links back to the official Aruba/HPE advisory when NVD carries the reference.

Latest Aruba Instant AP / InstantOS advisories

Low2.7Aruba

Low [CVE-2026-76738] Authenticated Buffer Overflow Vulnerability in the API Endpoint of HPE Networking Instant On Causes Denial-of-Service

A buffer overflow vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service, which recovers without manual intervention.

CVE-2026-76738
Instant APWireless & ControllersInstant
Sep 29, 2026
Low3.0Aruba

Low [CVE-2026-76737] Authenticated Local Path Traversal Vulnerability Leads to Denial-of-Service in HPE Networking Instant On

An authenticated path traversal vulnerability exists in the command line interface of HPE Networking Instant On. Successful exploitation could allow an attacker with administrative access to modify a limited set of files on the underlying operating system and to interrupt the normal operation of the affected service.

CVE-2026-76737
Instant APWireless & ControllersInstant
Sep 29, 2026
Low3.3Aruba

Low [CVE-2026-76736] Authenticated Local Buffer Overflow Vulnerability leads to Denial-of-Service in HPE Networking Instant On

A buffer overflow vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow a low-privilege authenticated local attacker to interrupt the normal operation of the affected service.

CVE-2026-76736
Instant APWireless & ControllersInstant
Sep 29, 2026

← All Aruba advisories