Multiple vulnerabilities in HPE Aruba Networking products (July 22, 2026)
Multiple vulnerabilities have been discovered in HPE Aruba Networking products. They allow an attacker to cause remote arbitrary code execution, a breach of data confidentiality, and a bypass of security policy.
CSIRTS triage
- What
- Multiple vulnerabilities in HPE Aruba Networking products could allow remote arbitrary code execution and data breaches.
- Who is affected
- Users of HPE Aruba Networking products.
- Urgency
- Remediation is critical due to the potential for remote code execution and data breaches.
- Action
- Update to the latest version of HPE Aruba Networking products.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Aruba Networking
Get an email when a new Aruba Networking advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0908/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-634540.55% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 43% of all scored CVEs.
- Moderate exploitation riskCVE-2026-448791.7% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 74% of all scored CVEs.
- Low exploitation riskCVE-2026-448780.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all scored CVEs.
- Low exploitation riskCVE-2026-448800.52% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all scored CVEs.
- Low exploitation riskCVE-2026-480200.87% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 55% of all scored CVEs.
- Low exploitation riskCVE-2026-353870.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all scored CVEs.
- Low exploitation riskCVE-2026-634530.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-63454 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-44879 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-44878 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-44880 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48020 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-35387 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-63453 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [high] IBM QRadar SIEM: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Aruba AOS-CX: Multiple Vulnerabilitiescert-bund
- medium[NEW] [medium] Aruba EdgeConnect: Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] OpenSSH: Multiple vulnerabilitiescert-bund
- highCVE-2026-44879: A vulnerability in the command line interface of ECOS devices could allow a highly privileged,…nvd
- highCVE-2026-44878: A vulnerability in the web-based management interface of an ECOS device could allow a highly p…nvd
- highCVE-2026-63454: An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of thi…nvd
- highCVE-2026-63453: Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful expl…nvd
- criticalHPE security advisory (AV26-727)cccs
- highCVE-2026-44880: A buffer overflow vulnerability was found in the command line interface of AOS-CX. Successful …nvd
- unknownPAN-SA-2026-0009 Informational Bulletin: Impact assessment of OSS CVEs in Prisma SD-WAN ION (Severity: INFORMA…paloalto
Recent advisories for HPE Aruba Networking
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownMultiple vulnerabilities in HPE Aruba Networking products (July 08, 2026)cert-fr-avis · 2026-07-08
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans le noyau Linux de SUSE (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux de Debian LTS (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans les produits IBM (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans Progress MOVEit Transfer (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux d'Ubuntu (31 juillet 2026)2026-07-31