# HPE Aruba Private 5G Core flaws patched

Published: 2026-08-10 · Severity: routine · Sectors: telecommunications
Canonical: https://vorant.io/reports/31f30431-cf36-5b4e-a659-90625d6b0784/hpe-aruba-private-5g-core-flaws-patched

> HPE Aruba Networking Private 5G Core versions before 1.26.1.3 contain two vulnerabilities allowing privilege escalation and security policy bypass.

The French national cybersecurity agency (ANSSI/CERT-FR) issued an advisory regarding multiple vulnerabilities discovered in HPE Aruba Networking's Private 5G Core product, affecting all versions prior to 1.26.1.3. The flaws, tracked as CVE-2026-33377 and CVE-2026-54763, could allow an attacker to escalate privileges and bypass security policy controls on the affected 5G core network infrastructure.

HPE published a corresponding security bulletin (HPESBNW05119) on August 7, 2026, detailing the vulnerabilities and providing patches. Organizations operating Private 5G Core deployments are advised to apply the vendor-supplied fixes to remediate the risk of privilege escalation and policy bypass. No indication of active exploitation is provided in the advisory.

## Mentioned in this report

- Vulnerabilities: CVE-2026-33377, CVE-2026-54763

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0989

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/31f30431-cf36-5b4e-a659-90625d6b0784/hpe-aruba-private-5g-core-flaws-patched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
