HPE Aruba RCE flaw hits Airwave, 5G Dashboard
A critical vulnerability in HPE Aruba Networking Airwave and Private 5G Management Dashboard allows remote code execution and denial of service; patches due July 2026.
HPE Aruba Networking disclosed a vulnerability affecting Airwave versions prior to 8.3.0.7 and Private 5G Management Dashboard versions prior to 1.25.2.2. The flaw, tracked as CVE-2026-42945, enables remote attackers to execute arbitrary code and trigger denial-of-service conditions without authentication or user interaction.
The vendor has published security advisory HPESBNW05064 and announced that corrective versions will be available in July 2026. Organizations running affected versions should prepare for immediate patching once updates are released.
Airwave is HPE's network management platform used for monitoring and managing wireless infrastructure, while the Private 5G Management Dashboard controls enterprise 5G deployments. Both products are deployed in enterprise and telecommunications environments, making this a priority concern for network operations teams.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0750
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free