# HPE Aruba RCE flaw hits Airwave, 5G Dashboard

Published: 2026-06-15 · Severity: high · Sectors: telecommunications
Canonical: https://vorant.io/reports/61987608-4d83-5317-9f3d-5e7d81753c09/hpe-aruba-rce-flaw-hits-airwave-5g-dashboard

> A critical vulnerability in HPE Aruba Networking Airwave and Private 5G Management Dashboard allows remote code execution and denial of service; patches expected July 2026.

HPE Aruba Networking has disclosed a vulnerability (CVE-2026-42945) affecting Airwave versions prior to 8.3.0.7 and Private 5G Management Dashboard versions prior to 1.25.2.2. The flaw enables remote attackers to execute arbitrary code and trigger denial-of-service conditions on vulnerable systems.

The vendor has announced that corrective versions will be available in July 2026. Organizations running affected versions of these network management products should monitor HPE Aruba's security bulletin for patch availability and plan remediation accordingly.

Given the remote exploitability and potential for code execution in network management infrastructure, affected organizations should consider interim mitigations such as network segmentation and access restrictions until patches can be applied.

## Mentioned in this report

- Vulnerabilities: CVE-2026-42945

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0750/

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/61987608-4d83-5317-9f3d-5e7d81753c09/hpe-aruba-rce-flaw-hits-airwave-5g-dashboard.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
