HPE Aruba patches Instant On, 5G Core flaws
CERT-FR advisory details multiple vulnerabilities in HPE Aruba Networking Instant On switches and Private 5G Core enabling DoS, data exposure, and security bypass.
CERT-FR has published an advisory covering multiple vulnerabilities in HPE Aruba Networking products, specifically affecting Instant On Switch models 1830, 1930, and 1960 running versions prior to 3.4.0, and Private 5G Core versions prior to 1.26.1.1. The flaws, tracked as CVE-2026-39803, CVE-2026-39806, CVE-2026-40912, and CVE-2026-44877, could allow an attacker to trigger a remote denial of service, compromise data confidentiality, or bypass security policies.
HPE has released two security bulletins (HPESBNW05038 and HPESBNW05077) alongside patches. No evidence of active exploitation is mentioned in the advisory; organizations running affected switch or 5G core software should apply the vendor-supplied fixes as part of routine patch management.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0846
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free