Multiple RCE Flaws Patched in Aruba ClearPass
CERT-FR advises multiple vulnerabilities in HPE Aruba Networking ClearPass Policy Manager allow remote code execution, privilege escalation, and denial of service.
CERT-FR has published an advisory covering multiple vulnerabilities in HPE Aruba Networking ClearPass Policy Manager (CPPM), a widely deployed network access control (NAC) and policy management platform. The flaws affect CPPM versions 6.12.x prior to 6.12.8-HF, 6.14.x prior to 6.14.0, and all versions prior to 6.11.15. Successful exploitation of the more severe issues can result in remote arbitrary code execution, privilege escalation, and remote denial of service, while other issues may affect data integrity.
Five CVEs are referenced (CVE-2026-73769, CVE-2026-73786, CVE-2026-73787, CVE-2026-73788, CVE-2026-73789), tracked under HPE's security bulletin HPESBNW05130 (published 9 September 2026). No public exploitation in the wild is mentioned in the advisory. Given ClearPass's role as a network access control appliance often exposed to internal and sometimes external network segments, defenders running affected versions should prioritize patching, as compromise could provide an attacker with a foothold to manipulate network access policies or escalate privileges within the environment.
Defenders should identify all ClearPass Policy Manager instances in their estate, confirm software versions against the affected ranges, and apply the vendor-supplied hotfixes or upgrade to non-vulnerable releases (6.12.8-HF or later, 6.14.0 or later, 6.11.15 or later) as detailed in the HPE Aruba Networking bulletin. No specific IOCs or detection signatures were provided in this advisory; monitoring should focus on unusual administrative activity, unexpected service crashes, or anomalous configuration changes on ClearPass appliances until patches are applied.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1151
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free