news.mlab.sh
Back to the feed
vulnerability

Multiples vulnérabilités dans HPE Aruba Networking ClearPass Policy Manager (10 septembre 2026)

HighCVSS 7.5
Summary

Multiple vulnerabilities have been discovered in HPE Aruba Networking ClearPass Policy Manager, allowing attackers to execute arbitrary code, escalate privileges, and cause denial of service. These vulnerabilities affect versions 6.12.x prior to 6.12.8-HF, 6.14.x prior to 6.14.0, and older versions of the Policy Manager. HPE has released security bulletins with patches to address these issues.

Multiple vulnerabilities have been identified within HPE Aruba Networking ClearPass Policy Manager. These weaknesses could enable attackers to execute arbitrary code remotely, elevate their privileges, and induce a denial of service. The affected versions include ClearPass Policy Manager (CPPM) versions 6.12.x prior to 6.12.8-HF, ClearPass Policy Manager (CPPM) versions 6.14.x prior to 6.14.0, and older versions of the Policy Manager. HPE has released a security bulletin to address these issues. The bulletin can be found at https://csaf.arubanetworking.hpe.com/2026/hpe_networking_-_hpesbnw05130.txt. The vulnerabilities are identified by CVE-2026-73769, CVE-2026-73786, CVE-2026-73787, CVE-2026-73788, and CVE-2026-73789.

Read the full article at CERT-FR