# CERT-FR flags multiple Aruba Instant On flaws

Published: 2026-09-30 · Severity: routine · Sectors: technology, infrastructure
Canonical: https://vorant.io/reports/fe0aa352-cd50-5475-a1e7-48b85229fbeb/cert-fr-flags-multiple-aruba-instant-on-flaws

> CERT-FR advisory covers 17 vulnerabilities in HPE Aruba Networking Instant On before 3.4.2.0, including RCE, privilege escalation, and DoS risks.

CERT-FR published an advisory summarizing multiple vulnerabilities disclosed by HPE in its Aruba Networking Instant On product line, affecting all versions prior to 3.4.2.0. The vulnerabilities collectively enable a range of impacts including remote arbitrary code execution, privilege escalation, remote denial of service, server-side request forgery (SSRF), security policy bypass, and confidentiality breaches. No indication is given that these vulnerabilities are being exploited in the wild.

The advisory references HPE's own security bulletin (HPESBNW05150, published 29 September 2026) and lists 17 associated CVE identifiers without individual technical descriptions, as is typical for CERT-FR bulletins that point to vendor advisories for remediation details. Defenders running Instant On network infrastructure should treat this as a standard patch-management advisory: identify all Instant On deployments, confirm firmware version, and apply the vendor patch bringing systems to 3.4.2.0 or later. Given the range of impacts, particularly RCE and privilege escalation on network access infrastructure, prompt patching is recommended even absent evidence of active exploitation.

## Mentioned in this report

- Vulnerabilities: CVE-2026-76721, CVE-2026-76722, CVE-2026-76723, CVE-2026-76724, CVE-2026-76725, CVE-2026-76726, CVE-2026-76727, CVE-2026-76728, CVE-2026-76729, CVE-2026-76730, CVE-2026-76731, CVE-2026-76732, CVE-2026-76733, CVE-2026-76734, CVE-2026-76735, CVE-2026-76736, CVE-2026-76737, CVE-2026-76738

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1238

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/fe0aa352-cd50-5475-a1e7-48b85229fbeb/cert-fr-flags-multiple-aruba-instant-on-flaws.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
