# HPE Aruba Networking AOS-CX contains a security policy bypass vulnerability…

Published: 2026-06-03 · Severity: high
Canonical: https://vorant.io/reports/52de364a-4c2a-4870-a058-689b41a9ac2c/hpe-aruba-networking-aos-cx-contains-a-security-policy-bypass-vulnerability

> HPE Aruba Networking AOS-CX contains a security policy bypass vulnerability (CVE-2024-39894) affecting multiple 10.x versions prior to patched releases.

A security policy bypass vulnerability has been identified in HPE Aruba Networking AOS-CX operating system. The vulnerability affects multiple version branches of ArubaOS-CX, specifically versions 10.10.x prior to 10.10.1160, 10.13.x prior to 10.13.1090, 10.15.x prior to 10.15.1010, and 10.16.x prior to 10.16.1010. The flaw allows an attacker to circumvent security policies on affected network devices.

Aruba Networks has released patches for all affected version branches. Organizations running AOS-CX in the affected version ranges should consult the vendor security bulletin HPESBNW05062 and apply the appropriate updates to their network infrastructure. The advisory was published by CERT-FR on behalf of ANSSI, referencing HPE Aruba's June 2, 2026 security bulletin.

Given the nature of the vulnerability as a security policy bypass in enterprise network switching infrastructure, organizations should prioritize assessment and remediation. Network devices that enforce security policies are critical control points, and bypass vulnerabilities can undermine network segmentation and access control mechanisms.

## Mentioned in this report

- Vulnerabilities: CVE-2024-39894

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0683

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/52de364a-4c2a-4870-a058-689b41a9ac2c/hpe-aruba-networking-aos-cx-contains-a-security-policy-bypass-vulnerability.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
