Skip to content
VulniPulse

HPE Aruba Networking Security Advisories & CVEs

293 advisories tracked · HPE Aruba Networking Security Advisories (PSIRT) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Aruba CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your Aruba device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Aruba's recent advisories.

Official source

HPE Aruba Networking Security Advisories (PSIRT) via NVD

Aruba's PSIRT bulletin portal (arubanetworks.com) is a JavaScript app with no stable public feed, so VulniPulse ingests Aruba's CVEs from NVD. Aruba publishes under the shared HPE CNA (security-alert@hpe.com), which also covers non-networking HPE products — so this feed is filtered to the full HPE Aruba Networking portfolio: ClearPass, AOS-8 mobility controllers, AOS-10 gateways and APs, Instant APs, AOS-CX and legacy AOS-Switch, Aruba Central, Fabric Composer and EdgeConnect/Silver Peak SD-WAN. Each entry links back to the official Aruba/HPE advisory when NVD carries the reference.

Latest Aruba advisories

High8.1Aruba

High [CVE-2026-73711] Unauthenticated Privilege Escalation allows Administrative Access in HPE Networking Fabric Composer API

A privilege escalation vulnerability exists in the API endpoint of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated remote attacker to gain administrative privileges leading to complete compromise of the HPE Networking Fabric Composer host.

CVE-2026-73711
Fabric Composer
Sep 1, 2026
High8.2Aruba

High [CVE-2026-73710] Unauthenticated Denial of Service Vulnerabilities in API Endpoint of HPE Networking Fabric Composer

Vulnerabilities in an API endpoint of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to make limited unauthorized modifications to the underlying operating system and disrupt the availability of the affected system, requiring manual intervention to restore functionality.

CVE-2026-73710
Fabric Composer
Sep 1, 2026
High8.3Aruba

High [CVE-2026-73709] Unauthenticated Remote Code Execution during HPE Networking Fabric Composer Installation Process

A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an unauthenticated adjacent attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met.

CVE-2026-73709
Fabric Composer
Sep 1, 2026
High8.3Aruba

High [CVE-2026-73708] Fault in Business Logic allows Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer

A business logic vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to obtain elevated privileges and modify settings beyond what is authorized by the user's existing privilege level on a vulnerable system.

CVE-2026-73708
Fabric Composer
Sep 1, 2026
High8.5Aruba

High [CVE-2026-73707] Authenticated Privilege Escalation via Broken Access Control in HPE Networking Fabric Composer API

Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to complete state-changing actions that should not be allowed by their current level of authorization on the platform, including changes to the configuration of systems managed by the affected product.

CVE-2026-73707
Fabric ComposerWireless & Controllers
Sep 1, 2026
High8.6Aruba

High [CVE-2026-73706] Authentication Bypass in the API of HPE Networking Fabric Composer allows Data Exposure and Unauthorized Changes

A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to obtain limited system information and to change the state of certain settings of a vulnerable system. Successful exploitation could allow an attacker to gain insight into internal services and workflows and to make unauthorized changes that may disrupt the normal operation of the affected service.

CVE-2026-73706
Fabric Composer
Sep 1, 2026
High8.8Aruba

High [CVE-2026-73705] Authenticated Arbitrary File Write leads to Remote Code Execution in HPE Networking Fabric Composer

An arbitrary file write vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary commands on the underlying operating system, leading to complete compromise of the affected system.

CVE-2026-73705
Fabric Composer
Sep 1, 2026
High8.8Aruba

High [CVE-2026-73704] Authenticated Command Injection Leading to Administrative Access in HPE Networking Fabric Composer API

A command sanitization bypass exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escalate their permissions to those of an administrative user, leading to complete compromise of the affected system.

CVE-2026-73704
Fabric Composer
Sep 1, 2026
High8.8Aruba

High [CVE-2026-73703] Unauthenticated Stored Cross-Site Scripting (XSS) Vulnerability in HPE Networking Fabric Composer Web-Based Management Interface

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated adjacent attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.

CVE-2026-73703
Fabric Composer
Sep 1, 2026
High8.8Aruba

High [CVE-2026-73702] Authenticated Privilege Escalation Vulnerability in the API of HPE Networking Fabric Composer

A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escalate their permissions to those of an administrative user, leading to complete system compromise.

CVE-2026-73702
Fabric Composer
Sep 1, 2026
Medium4.9Aruba Updated

Medium [CVE-2026-73783] AOS-CX: Stack overflow vulnerabilities exist in an API endpoint of AOS-CX

Stack overflow vulnerabilities exist in an API endpoint of AOS-CX. Successful exploitation could allow an authenticated malicious actor to cause a denial-of-service condition on the affected system.

CVE-2026-73783
AOS-CXSwitches (AOS-CX)
Sep 1, 2026
Medium6.5Aruba

Medium [CVE-2026-73772] AOS-CX: Buffer overflow vulnerabilities exist in an underlying service of AOS-CX that could lead to an unauthenticated denial-of-service condition by sending specially crafted packets to the affected device

Buffer overflow vulnerabilities exist in an underlying service of AOS-CX that could lead to an unauthenticated denial-of-service condition by sending specially crafted packets to the affected device. Successful exploitation of these vulnerabilities results in a disruption of normal operation of the underlying operating system.

CVE-2026-73772
AOS-CXSwitches (AOS-CX)
Sep 1, 2026
Medium6.6Aruba

Medium [CVE-2026-73762] AOS-CX: vulnerability has been identified in the API endpoint of AOS-CX that could allow a remote actor to circumvent existing access controls

A vulnerability has been identified in the API endpoint of AOS-CX that could allow a remote actor to circumvent existing access controls. In some cases this could enable unauthorized access to management functionality that should be restricted by the configured access control policy.

CVE-2026-73762
AOS-CXSwitches (AOS-CX)
Sep 1, 2026
Medium6.5Aruba

Medium [CVE-2026-73761] AOS-CX: out-of-bounds read vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated information disclosure by sending a specially crafted packet

An out-of-bounds read vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated information disclosure by sending a specially crafted packet. Successful exploitation of this vulnerability results in the ability to disclose sensitive information from the underlying operating system.

CVE-2026-73761
AOS-CXSwitches (AOS-CX)
Sep 1, 2026
Medium6.5Aruba

Medium [CVE-2026-73760] AOS-CX: authenticated Path Traversal vulnerability exists in AOS-CX

An authenticated Path Traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to read arbitrary files from the web-based management interface of the underlying operating system, which could lead to remote unauthorized access to files.

CVE-2026-73760
AOS-CXSwitches (AOS-CX)
Sep 1, 2026
Medium6.5Aruba

Medium [CVE-2026-73759] AOS-CX: Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-of-service condition by sending specially crafted packets

Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-of-service condition by sending specially crafted packets. Successful exploitation of these vulnerabilities results in disruption of normal operation on affected devices.

CVE-2026-73759
AOS-CXSwitches (AOS-CX)
Sep 1, 2026
Medium6.5Aruba

Medium [CVE-2026-73758] AOS-CX: privilege escalation vulnerability exists in the API endpoint of AOS-CX

A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulnerable system.

CVE-2026-73758
AOS-CXSwitches (AOS-CX)
Sep 1, 2026
Medium6.4Aruba

Medium [CVE-2026-73757] AOS-CX: vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a server-side request forgery (SSRF) attack

A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a server-side request forgery (SSRF) attack. A successful exploit allows an attacker to enumerate information about the internal structure of the AOS-CX host, leading to potential disclosure and limited modification of sensitive information.

CVE-2026-73757
AOS-CXSwitches (AOS-CX)
Sep 1, 2026
Medium5.9Aruba

Medium [CVE-2026-73756] AOS-CX: vulnerability in an API endpoint of AOS-CX could allow a remote unauthenticated attacker to obtain sensitive information via a man-in-the-middle attack

A vulnerability in an API endpoint of AOS-CX could allow a remote unauthenticated attacker to obtain sensitive information via a man-in-the-middle attack. Successful exploitation allows an attacker to retrieve data which could be used to further compromise the confidentiality of the affected system.

CVE-2026-73756
AOS-CXSwitches (AOS-CX)
Sep 1, 2026
Medium5.7Aruba

Medium [CVE-2026-73755] AOS-CX: privilege escalation vulnerability exists in the API endpoint of AOS-CX

A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low-privilege operator user, after a required user action, to access sensitive information from the vulnerable system.

CVE-2026-73755
AOS-CXSwitches (AOS-CX)
Sep 1, 2026

← All vendors