Skip to content
VulniPulse

HPE Aruba Networking Security Advisories & CVEs

11 advisories tracked · HPE Aruba Networking Security Advisories (PSIRT) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Aruba CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your Aruba device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Aruba's recent advisories.

Official source

HPE Aruba Networking Security Advisories (PSIRT) via NVD

Aruba's PSIRT bulletin portal (arubanetworks.com) is a JavaScript app with no stable public feed, so VulniPulse ingests Aruba's CVEs from NVD. Aruba publishes under the shared HPE CNA (security-alert@hpe.com), which also covers non-networking HPE products — so this feed is filtered to the full HPE Aruba Networking portfolio: ClearPass, AOS-8 mobility controllers, AOS-10 gateways and APs, Instant APs, AOS-CX and legacy AOS-Switch, Aruba Central, Fabric Composer and EdgeConnect/Silver Peak SD-WAN. Each entry links back to the official Aruba/HPE advisory when NVD carries the reference.

Latest Aruba advisories

Low2.7Aruba

Low [CVE-2026-76738] Authenticated Buffer Overflow Vulnerability in the API Endpoint of HPE Networking Instant On Causes Denial-of-Service

A buffer overflow vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service, which recovers without manual intervention.

CVE-2026-76738
Instant APWireless & ControllersInstant
Sep 29, 2026
Low3.0Aruba

Low [CVE-2026-76737] Authenticated Local Path Traversal Vulnerability Leads to Denial-of-Service in HPE Networking Instant On

An authenticated path traversal vulnerability exists in the command line interface of HPE Networking Instant On. Successful exploitation could allow an attacker with administrative access to modify a limited set of files on the underlying operating system and to interrupt the normal operation of the affected service.

CVE-2026-76737
Instant APWireless & ControllersInstant
Sep 29, 2026
Low3.3Aruba

Low [CVE-2026-76736] Authenticated Local Buffer Overflow Vulnerability leads to Denial-of-Service in HPE Networking Instant On

A buffer overflow vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow a low-privilege authenticated local attacker to interrupt the normal operation of the affected service.

CVE-2026-76736
Instant APWireless & ControllersInstant
Sep 29, 2026
Low2.2Aruba

Low [CVE-2026-73748] Fabric Composer: vulnerability in the affected interface of HPE Networking Fabric Composer allows an attacker with administrative privileges to access sensitive information in a cleartext format

A vulnerability in the affected interface of HPE Networking Fabric Composer allows an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking Fabric Composer.

CVE-2026-73748
Fabric Composer
Sep 1, 2026
Low2.5Aruba

Low [CVE-2026-73747] Fabric Composer: local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer

A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user with local access to elevate their user privileges and make limited modifications on the affected system.

CVE-2026-73747
Fabric Composer
Sep 1, 2026
Low3.1Aruba

Low [CVE-2026-73746] Fabric Composer: denial-of-service vulnerability exists in the API of HPE Networking Fabric Composer that could allow an authenticated low privilege operator user to cause a denial of service

A denial-of-service vulnerability exists in the API of HPE Networking Fabric Composer that could allow an authenticated low privilege operator user to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service.

CVE-2026-73746
Fabric Composer
Sep 1, 2026
Low3.5Aruba

Low [CVE-2026-73744] Fabric Composer: denial-of-service vulnerability exists in the web-based management interface of HPE Networking Fabric Composer that could allow an authenticated low privilege operator user to cause a denial of service

A denial-of-service vulnerability exists in the web-based management interface of HPE Networking Fabric Composer that could allow an authenticated low privilege operator user to cause a denial of service. Successful exploitation could allow an attacker to disrupt the availability of the affected interface.

CVE-2026-73744
Fabric Composer
Sep 1, 2026
Low3.7Aruba

Low [CVE-2026-73743] Fabric Composer: vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to gain insight into some data handled by the affected interface

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to gain insight into some data handled by the affected interface. A successful exploit could allow an attacker to gain access to some data in a cleartext format possibly exposing other network infrastructure to further compromise.

CVE-2026-73743
Fabric Composer
Sep 1, 2026
Low3.1Aruba

Low [CVE-2026-73745] Fabric Composer: vulnerability in the API endpoint of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to view some information handled by the affected system

A vulnerability in the API endpoint of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to view some information handled by the affected system. Successful exploitation could allow an attacker to gain insight into internal services and workflows, increasing the risk of unauthorized access when combined with other vulnerabilities.

CVE-2026-73745
Fabric Composer
Sep 1, 2026
Low3.3Aruba

Low [CVE-2025-25040] vulnerability has been identified in the port ACL functionality of AOS-CX software running on the HPE Aruba Networking CX 9300…

A vulnerability has been identified in the port ACL functionality of AOS-CX software running on the HPE Aruba Networking CX 9300 Switch Series only and affects: - AOS-CX 10.14.xxxx: All patches - AOS-CX 10.15.xxxx: 10.15.1000 and below The vulnerability is specific to traffic originated by the CX 9300 switch platform and could allow an attacker to bypass ACL rules applied to routed ports on egress. As a result, port ACLs are not correctly enforced, which could lead to unauthorized traffic flow and violations of security policies. Egress VLAN ACLs and Routed VLAN ACLs are not affected by this vulnerability.

CVE-2025-25040
AOS-CXSwitches (AOS-CX)
Mar 18, 2025
Low3.7Aruba

Low [CVE-2024-25616] Aruba has identified certain configurations of ArubaOS that can

Aruba has identified certain configurations of ArubaOS that can lead to partial disclosure of sensitive information in the IKE_AUTH negotiation process. The scenarios in which disclosure of potentially sensitive information can occur are complex, and depend on factors beyond the control of attackers.

CVE-2024-25616
AOS-8 MobilityWireless & ControllersArubaOS
Mar 5, 2024

← All vendors