HPE Aruba Private 5G Core flaws patched
HPE Aruba Networking Private 5G Core versions before 1.26.1.3 contain two vulnerabilities allowing privilege escalation and security policy bypass.
The French national cybersecurity agency (ANSSI/CERT-FR) issued an advisory regarding multiple vulnerabilities discovered in HPE Aruba Networking's Private 5G Core product, affecting all versions prior to 1.26.1.3. The flaws, tracked as CVE-2026-33377 and CVE-2026-54763, could allow an attacker to escalate privileges and bypass security policy controls on the affected 5G core network infrastructure.
HPE published a corresponding security bulletin (HPESBNW05119) on August 7, 2026, detailing the vulnerabilities and providing patches. Organizations operating Private 5G Core deployments are advised to apply the vendor-supplied fixes to remediate the risk of privilege escalation and policy bypass. No indication of active exploitation is provided in the advisory.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0989
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free