# HPE Aruba RCE flaw hits Airwave, 5G Dashboard

Published: 2026-06-15 · Severity: critical · Sectors: telecommunications, technology
Canonical: https://vorant.io/reports/42a04c1e-64cd-4a44-94a8-0019ea6e32d8/hpe-aruba-rce-flaw-hits-airwave-5g-dashboard

> A critical vulnerability in HPE Aruba Networking Airwave and Private 5G Management Dashboard allows remote code execution and denial of service; patches due July 2026.

HPE Aruba Networking disclosed a vulnerability affecting Airwave versions prior to 8.3.0.7 and Private 5G Management Dashboard versions prior to 1.25.2.2. The flaw, tracked as CVE-2026-42945, enables remote attackers to execute arbitrary code and trigger denial-of-service conditions without authentication or user interaction.

The vendor has published security advisory HPESBNW05064 and announced that corrective versions will be available in July 2026. Organizations running affected versions should prepare for immediate patching once updates are released.

Airwave is HPE's network management platform used for monitoring and managing wireless infrastructure, while the Private 5G Management Dashboard controls enterprise 5G deployments. Both products are deployed in enterprise and telecommunications environments, making this a priority concern for network operations teams.

## Mentioned in this report

- Vulnerabilities: CVE-2026-42945

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0750

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/42a04c1e-64cd-4a44-94a8-0019ea6e32d8/hpe-aruba-rce-flaw-hits-airwave-5g-dashboard.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
