Skip to content
VulniPulse

HPE Aruba Networking Security Advisories & CVEs

293 advisories tracked · HPE Aruba Networking Security Advisories (PSIRT) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Aruba CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your Aruba device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Aruba's recent advisories.

Official source

HPE Aruba Networking Security Advisories (PSIRT) via NVD

Aruba's PSIRT bulletin portal (arubanetworks.com) is a JavaScript app with no stable public feed, so VulniPulse ingests Aruba's CVEs from NVD. Aruba publishes under the shared HPE CNA (security-alert@hpe.com), which also covers non-networking HPE products — so this feed is filtered to the full HPE Aruba Networking portfolio: ClearPass, AOS-8 mobility controllers, AOS-10 gateways and APs, Instant APs, AOS-CX and legacy AOS-Switch, Aruba Central, Fabric Composer and EdgeConnect/Silver Peak SD-WAN. Each entry links back to the official Aruba/HPE advisory when NVD carries the reference.

Latest Aruba advisories

High7.1Aruba

High [CVE-2026-73764] AOS-CX: Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls

Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable unauthorized modification of affected resources and limited disruption of affected services.

CVE-2026-73764
AOS-CXSwitches (AOS-CX)
Sep 1, 2026
High7.1Aruba

High [CVE-2026-73763] Unauthenticated Remote Command Execution in Management Component

A vulnerability exists in a management component that could allow an unauthenticated adjacent attacker to execute arbitrary commands. Successful exploitation could result in remote execution of arbitrary commands in the context of the affected utility. Affected product named by the advisory: AOS-CX.

CVE-2026-73763
AOS-CXSwitches (AOS-CX)
Sep 1, 2026
High8.8Aruba

High [CVE-2026-73753] Authenticated Remote Command Injection Vulnerabilities in AOS-CX Command Line Interface

Exploitation through affected command-line operations could allow an authenticated low-privileged user to execute arbitrary commands as a privileged user on the underlying operating system. Affected product named by the advisory: AOS-CX.

CVE-2026-73753
AOS-CXSwitches (AOS-CX)
Sep 1, 2026
High8.8Aruba Updated

High [CVE-2026-73752] AOS-CX: unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX

An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. Successful exploitation of this vulnerability allows an attacker to write arbitrary files to the underlying operating system, which could lead to remote code execution.

CVE-2026-73752
AOS-CXSwitches (AOS-CX)
Sep 1, 2026
High8.8Aruba

High [CVE-2026-73751] Authenticated Remote Command Injection in AOS-CX Web-based Management Interface

An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system. Affected product named by the advisory: AOS-CX.

CVE-2026-73751
AOS-CXSwitches (AOS-CX)
Sep 1, 2026
High8.8Aruba

High [CVE-2026-73750] Authenticated Buffer Overflow Vulnerabilities in AOS-CX API Endpoint Leads to Possible Code Execution

Vulnerabilities exist in the authentication module that may improperly process malformed or truncated input. An authenticated remote attacker could exploit these vulnerabilities by providing specially crafted input from a compromised or hostile authentication server. Successful exploitation could result in a Denial-of-Service or potential remote code execution with elevated privileges. Affected product named by the advisory: AOS-CX.

CVE-2026-73750
AOS-CXSwitches (AOS-CX)
Sep 1, 2026
High7.0Aruba

High [CVE-2026-73725] Fabric Composer: local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer

A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges, leading to a complete compromise of the affected host.

CVE-2026-73725
Fabric Composer
Sep 1, 2026
High7.1Aruba

High [CVE-2026-73724] Fabric Composer: Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer

Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulnerable system.

CVE-2026-73724
Fabric Composer
Sep 1, 2026
High7.1Aruba

High [CVE-2026-73723] Fabric Composer: privilege escalation vulnerability exists in the web-based management interface of HPE Networking Fabric Composer

A privilege escalation vulnerability exists in the web-based management interface of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to complete state-changing actions that should not be allowed by their current level of authorization on the platform.

CVE-2026-73723
Fabric Composer
Sep 1, 2026
High7.2Aruba

High [CVE-2026-73722] Fabric Composer: Command injection vulnerabilities in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated remote attacker to perform command injection against the affected system

Command injection vulnerabilities in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated remote attacker to perform command injection against the affected system. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.

CVE-2026-73722
Fabric Composer
Sep 1, 2026
High7.2Aruba

High [CVE-2026-73721] Fabric Composer: Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated remote attacker to conduct SQL injection attacks against the HPE Networking Fabric Composer instance

Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated remote attacker to conduct SQL injection attacks against the HPE Networking Fabric Composer instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database potentially leading to complete compromise of the HPE Networking Fabric Composer host.

CVE-2026-73721
Fabric Composer
Sep 1, 2026
High7.2Aruba

High [CVE-2026-73720] Fabric Composer: Insecure file operations in the API of HPE Networking Fabric Composer could allow an authenticated remote attacker to achieve remote code execution

Insecure file operations in the API of HPE Networking Fabric Composer could allow an authenticated remote attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.

CVE-2026-73720
Fabric Composer
Sep 1, 2026
High7.2Aruba

High [CVE-2026-73719] Authenticated Arbitrary File Write Vulnerability leads to Remote Code Execution in HPE Networking Fabric Composer

An arbitrary file write vulnerability exists in the API of HPE Networking Fabric Composer and could allow an authenticated administrative user to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying operating system.

CVE-2026-73719
Fabric Composer
Sep 1, 2026
High7.4Aruba

High [CVE-2026-73718] Unauthenticated Information Disclosure in Web Interface allows Sensitive Data Exposure in HPE Networking Fabric Composer

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to access sensitive information if the attacker can convince an authenticated user of the interface to interact with a specially crafted URL. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking Fabric Composer.

CVE-2026-73718
Fabric Composer
Sep 1, 2026
High7.5Aruba

High [CVE-2026-73717] Unauthenticated Command Injection Vulnerability in HPE Networking Fabric Composer Web-Based Management Interface

A command injection vulnerability exists in the web-based management interface of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

CVE-2026-73717
Fabric Composer
Sep 1, 2026
High7.5Aruba

High [CVE-2026-73716] Unauthenticated Remote Code Execution in HPE Networking Fabric Composer

A remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system, leading to complete compromise of the HPE Networking Fabric Composer host.

CVE-2026-73716
Fabric Composer
Sep 1, 2026
High7.5Aruba

High [CVE-2026-73715] Unauthenticated Denial-of-Service (DoS) Vulnerability in the API of HPE Networking Fabric Composer

A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to disrupt the availability of the affected interface.

CVE-2026-73715
Fabric Composer
Sep 1, 2026
High7.6Aruba

High [CVE-2026-73714] Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer API

A sensitive information disclosure vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to access data beyond what is authorized by the user's existing privilege level, potentially leading to further unauthorized access.

CVE-2026-73714
Fabric Composer
Sep 1, 2026
High7.8Aruba

High [CVE-2026-73713] Local Privilege Escalation Vulnerabilities in HPE Networking Fabric Composer

Local privilege-escalation vulnerabilities have been discovered in HPE Networking Fabric Composer. Successful exploitation of these vulnerabilities could allow a local attacker to achieve arbitrary code execution with root privileges on the underlying operating system of the affected system.

CVE-2026-73713
Fabric Composer
Sep 1, 2026
High8.1Aruba

High [CVE-2026-73712] Unauthenticated Remote Code Execution in HPE Networking Fabric Composer API

A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

CVE-2026-73712
Fabric Composer
Sep 1, 2026

← All vendors