Aruba Products Multiple Vulnerabilities
September 7, 2026 · HKCERT · Severity: HIGH
Multiple vulnerabilities were identified in Aruba Products. A remote attacker could exploit these vulnerabilities to trigger security restriction bypass, denial of service condition, cross-site scripting, sensitive information disclosure, elevation of privilege and remote code execution on the targeted system. Impact Remote Code Execution Security Restriction Bypass Denial of Service Cross-Site Scripting Information Disclosure Elevation of Privilege System / Technologies affected AOS-CX 10.18.0001 AOS-CX 10.17.1021 and below AOS-CX 10.16.1051 and below AOS-CX 10.13.1180 and below AOS-CX 10.10.1180 and below (EOM) Solutions Before installation of the software, please visit the vendor web-site for more details. Apply fixes issued by the vendor: https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US
Key Takeaways
- Multiple Aruba product vulnerabilities have been disclosed, enabling security bypass, DoS, XSS, information disclosure, and RCE.
- Organizations using Aruba networking equipment should review the advisory and prioritize patching based on their exposure to each attack vector.
- The broad range of impact across confidentiality, availability, and integrity makes Aruba devices a critical patch priority.