Multiple vulnerabilities in HPE Aruba Networking products (02 September 2026)
Multiple vulnerabilities were discovered in HPE Aruba Networking products. Some of them allow an attacker to cause arbitrary remote code execution, privilege escalation and remote denial of service.
CSIRTS triage
- What
- Multiple vulnerabilities in HPE Aruba Networking products enable remote code execution, privilege escalation, and denial of service.
- Who is affected
- Deployments of affected HPE Aruba Networking products are vulnerable.
- Urgency
- Critical urgency due to remote code execution capability.
- Action
- Consult HPE's security advisory to identify affected products and versions, then apply patches.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1104/
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Aruba ArubaOS-CX: Multiple vulnerabilitiescert-bund
- highCVE-2026-73781: A vulnerability in the web-based management interface of AOS-CX could allow an authenticated r…nvd
- highCVE-2026-73780: A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions…nvd
- highCVE-2026-73779: Vulnerabilities have been identified in the operating system of AOS-CX switches that could pot…nvd
- highCVE-2026-73778: A vulnerability exists in the Credential Manager component that may allow for unauthorized adm…nvd
- highCVE-2026-73776: A signature verification bypass vulnerability exists in the command line interface of AOS-CX. …nvd
- highCVE-2026-73775: Vulnerabilities in the API endpoint of AOS-CX could allow a remote attacker authenticated with…nvd
- highCVE-2026-73774: A buffer overflow vulnerability exists in the underlying operating system of AOS-CX that could…nvd
- highCVE-2026-73773: An unauthenticated Denial-of-Service (DoS) vulnerability exists in the API endpoint of AOS-CX.…nvd
- mediumCVE-2026-73772: Buffer overflow vulnerabilities exist in an underlying service of AOS-CX that could lead to an…nvd
- highCVE-2026-73771: An authentication vulnerability exists in the AOS-CX management interface and API that may all…nvd
- highCVE-2026-73770: An authenticated arbitrary file write vulnerability exists in AOS-CX. Successful exploitation …nvd
Recent advisories for HPE Aruba Networking
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownMultiple vulnerabilities in HPE Aruba Networking Private 5G Core (August 10, 2026)cert-fr-avis · 2026-08-10
- unknownMultiple vulnerabilities in HPE Aruba Networking EdgeConnect SD-WAN Orchestrator (August 5, 2026)cert-fr-avis · 2026-08-05
- unknownMultiple vulnerabilities in HPE Aruba Networking products (July 22, 2026)cert-fr-avis · 2026-07-22
- unknownMultiple vulnerabilities in HPE Aruba Networking products (July 08, 2026)cert-fr-avis · 2026-07-08
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Curl (02 September 2026)2026-09-02
- unknownMultiple vulnerabilities in Google Chrome (02 September 2026)2026-09-02
- unknownMultiple vulnerabilities in Mozilla products (02 September 2026)2026-09-02
- unknownMultiple vulnerabilities in Elastic products (02 September 2026)2026-09-02
- unknownMultiple vulnerabilities in SonicWall products (02 September 2026)2026-09-02