# Multiple flaws hit HPE Aruba Networking gear

Published: 2026-07-22 · Severity: medium · Sectors: telecommunications, technology
Canonical: https://vorant.io/reports/45df9fe8-6ca1-5c48-93a4-44541d5a7851/multiple-flaws-hit-hpe-aruba-networking-gear

> HPE Aruba Networking disclosed multiple vulnerabilities in AOS-CX, EdgeConnect SD-WAN, and Private 5G Core allowing remote code execution and data exposure.

ANSSI-CERT-FR issued an advisory covering multiple vulnerabilities affecting HPE Aruba Networking products, including AOS-CX switch software, EdgeConnect SD-WAN Gateway (ECOS), and Private 5G Core. The flaws could allow an attacker to achieve remote code execution, compromise data confidentiality, or bypass security policies.

Affected versions span several branches of AOS-CX (10.13.x, 10.16.x, 10.17.x, 10.18.x), ECOS (9.4.x through 9.7.x), and Private 5G Core prior to 1.26.1.2. Seven CVEs are referenced across three HPE Aruba security bulletins published in July 2026. No evidence of active exploitation is mentioned in the advisory; organizations running affected products should apply the vendor's patches as detailed in the referenced HPE bulletins.

## Mentioned in this report

- Vulnerabilities: CVE-2026-35387, CVE-2026-44878, CVE-2026-44879, CVE-2026-44880, CVE-2026-48020, CVE-2026-63453, CVE-2026-63454

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0908

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/45df9fe8-6ca1-5c48-93a4-44541d5a7851/multiple-flaws-hit-hpe-aruba-networking-gear.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
