Skip to content
VulniPulse

HPE Aruba Networking Instant AP / InstantOS Vulnerabilities & Security Advisories

29 advisories tracked · HPE Aruba Networking Security Advisories (PSIRT) via NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published HPE Aruba Networking advisory that VulniPulse classified as Instant AP / InstantOS, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 5 critical, 9 high, 12 medium, 3 low.

Android app · Google Play

Monitor Aruba CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

HPE Aruba Networking Security Advisories (PSIRT) via NVD

Aruba's PSIRT bulletin portal (arubanetworks.com) is a JavaScript app with no stable public feed, so VulniPulse ingests Aruba's CVEs from NVD. Aruba publishes under the shared HPE CNA (security-alert@hpe.com), which also covers non-networking HPE products — so this feed is filtered to the full HPE Aruba Networking portfolio: ClearPass, AOS-8 mobility controllers, AOS-10 gateways and APs, Instant APs, AOS-CX and legacy AOS-Switch, Aruba Central, Fabric Composer and EdgeConnect/Silver Peak SD-WAN. Each entry links back to the official Aruba/HPE advisory when NVD carries the reference.

Latest Aruba Instant AP / InstantOS advisories

Medium4.1Aruba

Medium [CVE-2026-76735] Authenticated Local Sensitive Information Disclosure in HPE Networking Instant On

A sensitive information disclosure vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow an authenticated local attacker with high privileges to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking Instant On, only if certain preconditions outside of the attacker's control are met.

CVE-2026-76735
Instant APWireless & ControllersInstant
Sep 29, 2026
Medium4.8Aruba

Medium [CVE-2026-76734] Unauthenticated Memory Corruption Vulnerability leads to Denial-of-Service in HPE Networking Instant On

A memory corruption vulnerability in the affected interface of HPE Networking Instant On could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service and to access some limited information within the affected component.

CVE-2026-76734
Instant APWireless & ControllersInstant
Sep 29, 2026
Medium4.9Aruba

Medium [CVE-2026-76733] Authenticated Denial-of-Service Vulnerability in HPE Networking Instant On API Endpoint

A denial-of-service vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service, which resumes without manual intervention.

CVE-2026-76733
Instant APWireless & ControllersInstant
Sep 29, 2026
Medium6.4Aruba

Medium [CVE-2026-76732] Authenticated Local Privilege Escalation Vulnerability in a Daemon of HPE Networking Instant ON

A local privilege-escalation vulnerability has been discovered in the affected daemon of HPE Networking Instant ON. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges if certain preconditions are met outside of the attacker's control.

CVE-2026-76732
Instant APWireless & ControllersInstant
Sep 29, 2026
Medium6.5Aruba

Medium [CVE-2026-76731] Authentication Bypass in the Captive Portal of HPE Networking Instant On

An authentication bypass vulnerability in the captive portal of HPE Networking Instant On could allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain limited access to some data and to make limited changes within the affected component.

CVE-2026-76731
Instant APWireless & ControllersInstant
Sep 29, 2026
Medium6.5Aruba

Medium [CVE-2026-76730] Improper PAPI Packet handling leads to unauthorized access in HPE Networking Instant ON APs

An authentication bypass vulnerability exists in the PAPI protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to circumvent certain existing authentication mechanisms and send unauthorized network traffic to the target device.

CVE-2026-76730
Instant APWireless & ControllersInstant
Sep 29, 2026
Medium6.6Aruba

Medium [CVE-2026-76729] Authenticated Format String Vulnerability allows Memory Corruption in HPE Networking Instant ON API Endpoint

A format string vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to cause memory corruption with a modified input. Successful exploitation could allow an attacker to provoke a denial-of-service condition or remote code execution in the affected system function.

CVE-2026-76729
Instant APWireless & ControllersInstant
Sep 29, 2026
Medium5.3Aruba

Medium [CVE-2026-23822] AOS-8: vulnerability in the XML handling component of AOS-8 DHCP services could allow an unauthenticated remote attacker to trigger a denial-of-service condition

A vulnerability in the XML handling component of AOS-8 DHCP services could allow an unauthenticated remote attacker to trigger a denial-of-service condition. Successful exploitation could allow an attacker to cause excessive resource consumption upon user interaction, leading to service disruption or reduced availability of the affected system. NOTE: This vulnerability only impacts Access Points running AOS Instant 8.x.x.x Affected product named by the advisory: Instant AP.

CVE-2026-23822
Instant APWireless & ControllersInstantArubaOS
May 12, 2026
Medium6.5Aruba

Medium [CVE-2025-37148] vulnerability in the parsing of ethernet frames in AOS-8 Instant and AOS 10 could

A vulnerability in the parsing of ethernet frames in AOS-8 Instant and AOS 10 could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to potentially disrupt network services and require manual intervention to restore functionality.

CVE-2025-37148
AOS-10Instant APWireless & ControllersInstant
Oct 14, 2025
Medium6.0Aruba

Medium [CVE-2025-27079] vulnerability in the file creation process on the command line interface of AOS-8 Instant and AOS-10 AP could

A vulnerability in the file creation process on the command line interface of AOS-8 Instant and AOS-10 AP could allow an authenticated remote attacker to perform remote code execution (RCE). Successful exploitation could allow an attacker to execute arbitrary operating system commands on the underlying operating system leading to potential system compromise.

CVE-2025-27079
AOS-10Instant APWireless & ControllersInstant
Apr 8, 2025
Medium6.5Aruba

Medium [CVE-2025-27078] vulnerability in a system binary of AOS-8 Instant and AOS-10 AP could

A vulnerability in a system binary of AOS-8 Instant and AOS-10 AP could allow an authenticated remote attacker to inject commands into the underlying operating system while using the CLI. Successful exploitation could lead to complete system compromise.

CVE-2025-27078
AOS-10Instant APWireless & ControllersInstant
Apr 8, 2025
Medium6.8Aruba

Medium [CVE-2024-47464] AOS-10: authenticated Path Traversal vulnerability exists in Instant AOS-8 and AOS-10.

An authenticated Path Traversal vulnerability exists in Instant AOS-8 and AOS-10. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location from the command line interface of the underlying operating system, which could lead to a remote unauthorized access to files.

CVE-2024-47464
AOS-10Instant APWireless & ControllersInstant
Nov 5, 2024

← All Aruba advisories