news.mlab.sh
Back to the feed
vulnerability

Multiples vulnérabilités dans les produits HPE Aruba Networking (22 juillet 2026)

High
Summary

Multiple vulnerabilities have been discovered in HPE Aruba Networking products, allowing an attacker to execute arbitrary code, compromise data confidentiality, and bypass security policies. These vulnerabilities affect several versions of AOS-CX, EdgeConnect SD-WAN Gateway, and Private 5G Core, requiring immediate patching to mitigate the risk.

A security advisory from CERT-FR details multiple vulnerabilities within HPE Aruba Networking products. These vulnerabilities enable an attacker to execute arbitrary code remotely, potentially leading to full system compromise. Furthermore, attackers can bypass security policies, granting them unauthorized access and control. The affected products include various versions of AOS-CX, EdgeConnect SD-WAN Gateway (ECOS), and Private 5G Core. Specific versions impacted are listed in the advisory. The vulnerabilities are addressed through the HPE Aruba Networking security bulletins. CERT-FR has linked to the relevant security bulletins for detailed information and patching instructions. The CVE identifiers associated with these vulnerabilities are CVE-2026-35387, CVE-2026-44878, CVE-2026-44879, CVE-2026-44880, CVE-2026-48020, and CVE-2026-63453. Users are strongly advised to consult the linked security bulletins for specific instructions on how to apply the necessary patches.

Read the full article at CERT-FR