Skip to content
VulniPulse

HPE Aruba Networking Security Advisories & CVEs

57 advisories tracked · HPE Aruba Networking Security Advisories (PSIRT) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Aruba CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your Aruba device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Aruba's recent advisories.

Official source

HPE Aruba Networking Security Advisories (PSIRT) via NVD

Aruba's PSIRT bulletin portal (arubanetworks.com) is a JavaScript app with no stable public feed, so VulniPulse ingests Aruba's CVEs from NVD. Aruba publishes under the shared HPE CNA (security-alert@hpe.com), which also covers non-networking HPE products — so this feed is filtered to the full HPE Aruba Networking portfolio: ClearPass, AOS-8 mobility controllers, AOS-10 gateways and APs, Instant APs, AOS-CX and legacy AOS-Switch, Aruba Central, Fabric Composer and EdgeConnect/Silver Peak SD-WAN. Each entry links back to the official Aruba/HPE advisory when NVD carries the reference.

Latest Aruba advisories

High7.2Aruba

High [CVE-2026-23816] vulnerability in the command line interface of AOS-CX Switches could

A vulnerability in the command line interface of AOS-CX Switches could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.

CVE-2026-23816
AOS-CXSwitches (AOS-CX)
Mar 11, 2026
High7.2Aruba

High [CVE-2026-23815] vulnerability in a custom binary used in AOS-CX Switches' CLI could

A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute unauthorized commands.

CVE-2026-23815
AOS-CXSwitches (AOS-CX)
Mar 11, 2026
High8.8Aruba

High [CVE-2026-23814] vulnerability in the command parameters of a certain AOS-CX CLI command could

A vulnerability in the command parameters of a certain AOS-CX CLI command could allow a low-privilege authenticated remote attacker to inject malicious commands resulting in unwanted behavior.

CVE-2026-23814
AOS-CXSwitches (AOS-CX)
Mar 11, 2026
High7.8Aruba

High [CVE-2026-23599] local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking ClearPass OnGuard Software for Linux

A local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking ClearPass OnGuard Software for Linux. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges.

CVE-2026-23599
ClearPass
Feb 18, 2026
High7.5Aruba

High [CVE-2026-23593] vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could

A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could allow an unauthenticated remote attacker to view some system files. Successful exploitation could allow an attacker to read files within the affected directory.

CVE-2026-23593
Fabric Composer
Jan 27, 2026
High7.2Aruba

High [CVE-2026-23592] Insecure file operations in HPE Aruba Networking Fabric Composer’s backup functionality could

Insecure file operations in HPE Aruba Networking Fabric Composer’s backup functionality could allow authenticated attackers to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.

CVE-2026-23592
Fabric Composer
Jan 27, 2026
High7.2Aruba

High [CVE-2025-37183] Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could

Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL injection attacks. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database, potentially leading to unauthorized data access or data manipulation.

CVE-2025-37183
EdgeConnect SD-WAN
Jan 14, 2026
High7.8Aruba

High [CVE-2025-37186] local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking Virtual Intranet Access (VIA) client

A local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking Virtual Intranet Access (VIA) client. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges.

CVE-2025-37186
Virtual Intranet AccessWireless & Controllers
Jan 13, 2026
High7.2Aruba

High [CVE-2025-37175] Arbitrary file upload vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or…

Arbitrary file upload vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor to upload arbitrary files as a privilege user and execute arbitrary commands on the underlying operating system.

CVE-2025-37175
AOS-10AOS-8 MobilityWireless & ControllersMobility Conductor
Jan 13, 2026
High7.2Aruba

High [CVE-2025-37174] AOS-10: Authenticated arbitrary file write vulnerability exists in the web-based management interface of mobility conductors running…

Authenticated arbitrary file write vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor to create or modify arbitrary files and execute arbitrary commands as a privileged user on the underlying operating system.

CVE-2025-37174
AOS-10AOS-8 MobilityWireless & ControllersMobility Conductor
Jan 13, 2026
High7.2Aruba

High [CVE-2025-37173] AOS-10: improper input handling vulnerability exists in the web-based management interface of mobility conductors running either…

An improper input handling vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor with valid credentials to trigger unintended behavior on the affected system.

CVE-2025-37173
AOS-10AOS-8 MobilityWireless & ControllersMobility Conductor
Jan 13, 2026
High7.2Aruba

High [CVE-2025-37172] Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8…

Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system.

CVE-2025-37172
AOS-8 MobilityWireless & ControllersMobility ConductorArubaOS
Jan 13, 2026
High7.2Aruba

High [CVE-2025-37169] AOS-10: stack overflow vulnerability exists in the AOS-10 web-based management interface of a Mobility Gateway.

A stack overflow vulnerability exists in the AOS-10 web-based management interface of a Mobility Gateway. Successful exploitation could allow an authenticated malicious actor to execute arbitrary code as a privileged user on the underlying operating system.

CVE-2025-37169
AOS-10Wireless & ControllersArubaOS
Jan 13, 2026
High8.2Aruba

High [CVE-2025-37168] Arbitrary file deletion vulnerability have been identified in a system function of mobility conductors running AOS-8 operating…

Arbitrary file deletion vulnerability have been identified in a system function of mobility conductors running AOS-8 operating system. Successful exploitation of this vulnerability could allow an unauthenticated remote malicious actor to delete arbitrary files within the affected system and potentially result in denial-of-service conditions on affected devices.

CVE-2025-37168
AOS-8 MobilityWireless & ControllersMobility ConductorArubaOS
Jan 13, 2026
High7.2Aruba

High [CVE-2025-37134] authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating…

An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system.

CVE-2025-37134
AOS-8 MobilityWireless & ControllersMobility ConductorArubaOS
Oct 14, 2025
High7.2Aruba

High [CVE-2025-37132] arbitrary file write vulnerability exists in the web-based management interface of both the AOS-10 GW and AOS-8…

An arbitrary file write vulnerability exists in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to upload arbitrary files and execute arbitrary commands on the underlying operating system.

CVE-2025-37132
AOS-10AOS-8 MobilityWireless & ControllersMobility Conductor
Oct 14, 2025
High7.2Aruba

High [CVE-2025-37127] vulnerability in the cryptographic logic used by HPE Aruba Networking EdgeConnect SD-WAN Gateways could

A vulnerability in the cryptographic logic used by HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to gain shell access. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system, potentially leading to unauthorized access and control over the affected systems.

CVE-2025-37127
EdgeConnect SD-WAN
Sep 16, 2025
High7.2Aruba

High [CVE-2025-37126] vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN Gateways Command Line Interface

A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN Gateways Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute arbitrary commands as root on the underlying operating system.

CVE-2025-37126
EdgeConnect SD-WAN
Sep 16, 2025
High7.5Aruba

High [CVE-2025-37125] EdgeConnect: broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS).

A broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS). Successful exploitation could allow an attacker to bypass firewall protections, potentially leading to unauthorized traffic being handled improperly

CVE-2025-37125
EdgeConnect SD-WAN
Sep 16, 2025
High8.8Aruba

High [CVE-2025-37123] vulnerability in the command-line interface of HPE Aruba Networking EdgeConnect SD-WAN Gateways could

A vulnerability in the command-line interface of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying operating system.

CVE-2025-37123
EdgeConnect SD-WAN
Sep 16, 2025

← All vendors