news.mlab.sh
Back to the feed
vulnerability

Multiples vulnérabilités dans les produits HPE Aruba Networking (02 septembre 2026)

CriticalCVSS 9.6
Summary

Multiple vulnerabilities have been discovered in HPE Aruba Networking products, including the ability to cause remote code execution, privilege escalation, and denial-of-service attacks. Several of these vulnerabilities are present in older versions of AOS-CX and Fabric Composer. HPE recommends migrating to a supported version to mitigate these risks.

Multiple vulnerabilities have been discovered in HPE Aruba Networking products. These vulnerabilities can be exploited to cause remote code execution, privilege escalation, and denial-of-service attacks. Specifically, older versions of AOS-CX (versions prior to 10.13.1190, 10.16.1060, 10.17.1030, 10.18.1002, and all versions prior to 10.10.1181) and Fabric Composer (versions prior to 7.3.4) are affected. The vulnerabilities include, but are not limited to, SSRF (Server-Side Request Forgery), XSS (Cross-Site Scripting), SQL injection, and CSRF (Cross-Site Request Forgery). HPE has released security bulletins detailing these vulnerabilities and providing instructions for remediation. Users are strongly advised to migrate to a supported version of AOS-CX and Fabric Composer to address these security concerns. The relevant security bulletins are available at: https://csaf.arubanetworking.hpe.com/2026/hpe_networking_-_hpesbnw05133.txt and https://csaf.arubanetworking.hpe.com/2026/hpe_networking_-_hpesbnw05134.txt. Numerous CVE identifiers have been assigned to these vulnerabilities, including CVE-2026-19766, CVE-2026-73700, CVE-2026-73701, CVE-2026-73702, CVE-2026-73703, CVE-2026-73704, CVE-2026-73705, CVE-2026-73706, CVE-2026-73707, CVE-2026-73708, CVE-2026-73709, CVE-2026-73710, CVE-2026-73711, CVE-2026-73712, CVE-2026-73713, CVE-2026-73714, CVE-2026-73715, CVE-2026-73716, CVE-2026-73717, CVE-2026-73718, CVE-2026-73719, CVE-2026-73720, CVE-2026-73721, CVE-2026-73722, CVE-2026-73723, CVE-2026-73724, CVE-2026-73725, CVE-2026-73726, CVE-2026-73727, CVE-2026-73728, CVE-2026-73729, CVE-2026-73730, CVE-2026-73731, CVE-2026-73732, CVE-2026-73733, CVE-2026-73734, CVE-2026-73735, CVE-2026-73736, CVE-2026-73737, CVE-2026-73738, CVE-2026-73739, CVE-2026-73740, CVE-2026-73741, CVE-2026-73742, CVE-2026-73743, CVE-2026-73744, CVE-2026-73745, CVE-2026-73746, CVE-2026-73747, CVE-2026-73748, CVE-2026-73749, CVE-2026-73750, CVE-2026-73751, CVE-2026-73752, CVE-2026-73753, CVE-2026-73754, CVE-2026-73755, CVE-2026-73756, CVE-2026-73757, CVE-2026-73758, CVE-2026-73759, CVE-2026-73760, CVE-2026-73761, CVE-2026-73762, CVE-2026-73763, CVE-2026-73764, CVE-2026-73765, CVE-2026-73766, CVE-2026-73767, CVE-2026-73768, CVE-2026-73769, CVE-2026-73770, CVE-2026-73771, CVE-2026-73772, CVE-2026-73773, CVE-2026-73774, CVE-2026-73775, CVE-2026-73776, CVE-2026-73777, CVE-2026-73778, CVE-2026-73779, CVE-2026-73780, CVE-2026-73781, CVE-2026-73782, CVE-2026-73783.

Read the full article at CERT-FR