Skip to content
VulniPulse

HPE Aruba Networking Security Advisories & CVEs

34 advisories tracked · HPE Aruba Networking Security Advisories (PSIRT) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Aruba CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your Aruba device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Aruba's recent advisories.

Official source

HPE Aruba Networking Security Advisories (PSIRT) via NVD

Aruba's PSIRT bulletin portal (arubanetworks.com) is a JavaScript app with no stable public feed, so VulniPulse ingests Aruba's CVEs from NVD. Aruba publishes under the shared HPE CNA (security-alert@hpe.com), which also covers non-networking HPE products — so this feed is filtered to the full HPE Aruba Networking portfolio: ClearPass, AOS-8 mobility controllers, AOS-10 gateways and APs, Instant APs, AOS-CX and legacy AOS-Switch, Aruba Central, Fabric Composer and EdgeConnect/Silver Peak SD-WAN. Each entry links back to the official Aruba/HPE advisory when NVD carries the reference.

Latest Aruba advisories

Critical9.8Aruba

Critical [CVE-2026-76721] Unauthenticated Buffer Overflow Vulnerability leads to Remote Code Execution in HPE Networking Instant ON APs

Buffer overflow vulnerability exists in the affected interface of HPE Networking Instant ON that could allow an unauthenticated remote attacker to run arbitrary code on the underlying host. Successful exploitation could allow an attacker to execute arbitrary code as a privileged user on the underlying operating system.

CVE-2026-76721
Instant APWireless & ControllersInstant
Sep 29, 2026
Critical9.1Aruba

Critical [CVE-2026-76675] EdgeConnect: command injection vulnerability exists in the command line interface of EdgeConnect SD-WAN Gateways

A command injection vulnerability exists in the command line interface of EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with high privileges to execute arbitrary commands on the underlying operating system leading to complete system compromise.

CVE-2026-76675
EdgeConnect SD-WAN
Sep 15, 2026
Critical9.8Aruba

Critical [CVE-2026-76674] EdgeConnect: Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to execute arbitrary code

Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to execute arbitrary code. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

CVE-2026-76674
EdgeConnect SD-WAN
Sep 15, 2026
Critical9.8Aruba

Critical [CVE-2026-76673] EdgeConnect: Vulnerabilities have been identified in the API of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls

Vulnerabilities have been identified in the API of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the EdgeConnect SD-WAN Orchestrator host. Affected product named by the advisory: EdgeConnect SD-WAN Gateways.

CVE-2026-76673
EdgeConnect SD-WAN
Sep 15, 2026
Critical9.9Aruba

Critical [CVE-2026-76672] Authenticated Sensitive Information Disclosure in HPE Networking EdgeConnect SD-WAN Orchestrator

A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configuration information. An authenticated remote attacker with read-only privileges could exploit this vulnerability by sending a specially crafted request to the cache synchronization endpoint. Successful exploitation could result in the disclosure of sensitive third-party API tokens and credentials, potentially enabling lateral movement to external security platforms. Affected product named by the advisory: EdgeConnect SD-WAN Gateways.

CVE-2026-76672
EdgeConnect SD-WAN
Sep 15, 2026
Critical9.9Aruba

Critical [CVE-2026-76670] EdgeConnect: Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator

Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate their privileges to those of an administrative user, leading to complete system compromise. Affected product named by the advisory: EdgeConnect SD-WAN Gateways.

CVE-2026-76670
EdgeConnect SD-WAN
Sep 15, 2026
Critical9.8Aruba Updated

Critical [CVE-2026-73749] AOS-CX: Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input

Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service. Successful exploitation could result in remote code execution with elevated privileges.

CVE-2026-73749
AOS-CXSwitches (AOS-CX)
Sep 1, 2026
Critical10.0Aruba

Critical [CVE-2026-76658] Fabric Composer: vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts

A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system leading to complete system compromise.

CVE-2026-76658
Fabric Composer
Sep 1, 2026
Critical10.0Aruba

Critical [CVE-2026-76657] Fabric Composer: Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls

Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the HPE Networking Fabric Composer host.

CVE-2026-76657
Fabric Composer
Sep 1, 2026
Critical9.0Aruba

Critical [CVE-2026-73701] Unauthenticated Remote Code Execution in HPE Networking Fabric Composer

An unauthenticated remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer and could be exploited if certain preconditions outside of the attacker's control are met. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to execute arbitrary code as a privileged user on the underlying operating system, leading to complete compromise of the HPE Networking Fabric Composer host.

CVE-2026-73701
Fabric Composer
Sep 1, 2026
Critical9.0Aruba

Critical [CVE-2026-73700] Authenticated Stored Cross-Site Scripting Vulnerability (XSS) in HPE Networking Fabric Composer Web-Based Management Interface

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.

CVE-2026-73700
Fabric Composer
Sep 1, 2026
Critical9.6Aruba

Critical [CVE-2026-19766] Authentication Bypass leads to Administrative control of adjacent network hosts in HPE Networking Fabric Composer

An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated adjacent attacker to execute arbitrary code as a privileged user on the underlying operating system, leading to complete compromise of the AFC host.

CVE-2026-19766
Fabric Composer
Sep 1, 2026
Critical9.8Aruba

Critical [CVE-2026-63456] Authentication bypass via spoofed HTTP headers Orchestrator REST API

Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target system. Affected product named by the advisory: EdgeConnect SD-WAN Orchestrator.

CVE-2026-63456
EdgeConnect SD-WANWireless & Controllers
Aug 4, 2026
Critical9.8Aruba

Critical [CVE-2026-23813] vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially

A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable resetting the admin password.

CVE-2026-23813
AOS-CXSwitches (AOS-CX)
Mar 11, 2026

← All vendors