Skip to content
VulniPulse

HPE Aruba Networking Security Advisories & CVEs

293 advisories tracked · HPE Aruba Networking Security Advisories (PSIRT) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Aruba CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your Aruba device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Aruba's recent advisories.

Official source

HPE Aruba Networking Security Advisories (PSIRT) via NVD

Aruba's PSIRT bulletin portal (arubanetworks.com) is a JavaScript app with no stable public feed, so VulniPulse ingests Aruba's CVEs from NVD. Aruba publishes under the shared HPE CNA (security-alert@hpe.com), which also covers non-networking HPE products — so this feed is filtered to the full HPE Aruba Networking portfolio: ClearPass, AOS-8 mobility controllers, AOS-10 gateways and APs, Instant APs, AOS-CX and legacy AOS-Switch, Aruba Central, Fabric Composer and EdgeConnect/Silver Peak SD-WAN. Each entry links back to the official Aruba/HPE advisory when NVD carries the reference.

Latest Aruba advisories

Critical9.6Aruba

Critical [CVE-2026-76723] Unauthenticated Adjacent Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking Instant ON APS

Buffer overflow vulnerabilities exist in the affected interface of HPE Networking Instant ON APS that could allow an unauthenticated adjacent attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.

CVE-2026-76723
Instant APWireless & ControllersInstant
Sep 29, 2026
Critical9.8Aruba

Critical [CVE-2026-76722] Uncontrolled Format String Vulnerabilities lead to Remote Code Execution or Denial-of-Service in HPE Networking Instant ON APs

Uncontrolled Format string vulnerabilities exist in the affected interface of HPE Networking Instant ON APs that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation could result in a Denial-of-service or potential remote code execution.

CVE-2026-76722
Instant APWireless & ControllersInstant
Sep 29, 2026
Critical9.8Aruba

Critical [CVE-2026-76721] Unauthenticated Buffer Overflow Vulnerability leads to Remote Code Execution in HPE Networking Instant ON APs

Buffer overflow vulnerability exists in the affected interface of HPE Networking Instant ON that could allow an unauthenticated remote attacker to run arbitrary code on the underlying host. Successful exploitation could allow an attacker to execute arbitrary code as a privileged user on the underlying operating system.

CVE-2026-76721
Instant APWireless & ControllersInstant
Sep 29, 2026
High7.2Aruba

High [CVE-2026-76728] Authenticated Server-Side Request Forgery Leading to Remote Code Execution in HPE Networking Instant ON APs

A vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to conduct a server-side request forgery (SSRF) attack. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.

CVE-2026-76728
Instant APWireless & ControllersInstant
Sep 29, 2026
High7.2Aruba

High [CVE-2026-76727] Authenticated Command Injection Vulnerabilities in HPE Networking Instant ON

Command injection vulnerabilities exist in the affected interface of HPE Networking Instant ON that could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.

CVE-2026-76727
Instant APWireless & ControllersInstant
Sep 29, 2026
High8.1Aruba

High [CVE-2026-76726] Authentication Bypass Leading to Unauthorized Network Access in HPE Networking Instant ON API Endpoint

An authentication bypass vulnerability in the API endpoint of HPE Networking Instant ON could allow an unauthenticated remote attacker to bypass network access controls if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to obtain unauthorized access to restricted networks.

CVE-2026-76726
Instant APWireless & ControllersInstant
Sep 29, 2026
Medium4.1Aruba

Medium [CVE-2026-76735] Authenticated Local Sensitive Information Disclosure in HPE Networking Instant On

A sensitive information disclosure vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow an authenticated local attacker with high privileges to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking Instant On, only if certain preconditions outside of the attacker's control are met.

CVE-2026-76735
Instant APWireless & ControllersInstant
Sep 29, 2026
Medium4.8Aruba

Medium [CVE-2026-76734] Unauthenticated Memory Corruption Vulnerability leads to Denial-of-Service in HPE Networking Instant On

A memory corruption vulnerability in the affected interface of HPE Networking Instant On could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service and to access some limited information within the affected component.

CVE-2026-76734
Instant APWireless & ControllersInstant
Sep 29, 2026
Medium4.9Aruba

Medium [CVE-2026-76733] Authenticated Denial-of-Service Vulnerability in HPE Networking Instant On API Endpoint

A denial-of-service vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service, which resumes without manual intervention.

CVE-2026-76733
Instant APWireless & ControllersInstant
Sep 29, 2026
Medium6.4Aruba

Medium [CVE-2026-76732] Authenticated Local Privilege Escalation Vulnerability in a Daemon of HPE Networking Instant ON

A local privilege-escalation vulnerability has been discovered in the affected daemon of HPE Networking Instant ON. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges if certain preconditions are met outside of the attacker's control.

CVE-2026-76732
Instant APWireless & ControllersInstant
Sep 29, 2026
Medium6.5Aruba

Medium [CVE-2026-76731] Authentication Bypass in the Captive Portal of HPE Networking Instant On

An authentication bypass vulnerability in the captive portal of HPE Networking Instant On could allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain limited access to some data and to make limited changes within the affected component.

CVE-2026-76731
Instant APWireless & ControllersInstant
Sep 29, 2026
Medium6.5Aruba

Medium [CVE-2026-76730] Improper PAPI Packet handling leads to unauthorized access in HPE Networking Instant ON APs

An authentication bypass vulnerability exists in the PAPI protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to circumvent certain existing authentication mechanisms and send unauthorized network traffic to the target device.

CVE-2026-76730
Instant APWireless & ControllersInstant
Sep 29, 2026
Medium6.6Aruba

Medium [CVE-2026-76729] Authenticated Format String Vulnerability allows Memory Corruption in HPE Networking Instant ON API Endpoint

A format string vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to cause memory corruption with a modified input. Successful exploitation could allow an attacker to provoke a denial-of-service condition or remote code execution in the affected system function.

CVE-2026-76729
Instant APWireless & ControllersInstant
Sep 29, 2026
Low2.7Aruba

Low [CVE-2026-76738] Authenticated Buffer Overflow Vulnerability in the API Endpoint of HPE Networking Instant On Causes Denial-of-Service

A buffer overflow vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service, which recovers without manual intervention.

CVE-2026-76738
Instant APWireless & ControllersInstant
Sep 29, 2026
Low3.0Aruba

Low [CVE-2026-76737] Authenticated Local Path Traversal Vulnerability Leads to Denial-of-Service in HPE Networking Instant On

An authenticated path traversal vulnerability exists in the command line interface of HPE Networking Instant On. Successful exploitation could allow an attacker with administrative access to modify a limited set of files on the underlying operating system and to interrupt the normal operation of the affected service.

CVE-2026-76737
Instant APWireless & ControllersInstant
Sep 29, 2026
Low3.3Aruba

Low [CVE-2026-76736] Authenticated Local Buffer Overflow Vulnerability leads to Denial-of-Service in HPE Networking Instant On

A buffer overflow vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow a low-privilege authenticated local attacker to interrupt the normal operation of the affected service.

CVE-2026-76736
Instant APWireless & ControllersInstant
Sep 29, 2026
Critical9.1Aruba

Critical [CVE-2026-76675] EdgeConnect: command injection vulnerability exists in the command line interface of EdgeConnect SD-WAN Gateways

A command injection vulnerability exists in the command line interface of EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with high privileges to execute arbitrary commands on the underlying operating system leading to complete system compromise.

CVE-2026-76675
EdgeConnect SD-WAN
Sep 15, 2026
Critical9.8Aruba

Critical [CVE-2026-76674] EdgeConnect: Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to execute arbitrary code

Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to execute arbitrary code. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

CVE-2026-76674
EdgeConnect SD-WAN
Sep 15, 2026
Critical9.8Aruba

Critical [CVE-2026-76673] EdgeConnect: Vulnerabilities have been identified in the API of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls

Vulnerabilities have been identified in the API of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the EdgeConnect SD-WAN Orchestrator host. Affected product named by the advisory: EdgeConnect SD-WAN Gateways.

CVE-2026-76673
EdgeConnect SD-WAN
Sep 15, 2026
Critical9.9Aruba

Critical [CVE-2026-76672] Authenticated Sensitive Information Disclosure in HPE Networking EdgeConnect SD-WAN Orchestrator

A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configuration information. An authenticated remote attacker with read-only privileges could exploit this vulnerability by sending a specially crafted request to the cache synchronization endpoint. Successful exploitation could result in the disclosure of sensitive third-party API tokens and credentials, potentially enabling lateral movement to external security platforms. Affected product named by the advisory: EdgeConnect SD-WAN Gateways.

CVE-2026-76672
EdgeConnect SD-WAN
Sep 15, 2026

← All vendors