<!DOCTYPE html><html xmlns:msxsl="urn:schemas-microsoft-com:xslt" xmlns:xalan="http://xml.apache.org/xalan">
<head>
<META http-equiv="Content-Type" content="text/html; charset=UTF-8">
<meta content="width=device-width, initial-scale=1.0" name="viewport">
<title>HPESBNW05156 rev 1 - Multiple Vulnerabilities in HPE Networking AOS-Swtich (AOS-S)</title>
<meta content="text/html; charset=utf-8" http-equiv="Content-Type">
</head>
<body style="font-family: Arial, sans-serif, Verdana, Helvetica; color: black; font-size: smaller;">
<div id="docDisplayForSearch">
<table style="table-layout: fixed; width: 95%; margin-left:10px; margin-right:10px;" class="IE8" border="0" cellspacing="0" cellpadding="0">
<tr>
<td style="width: 95% ;WHITE-SPACE: normal; word-wrap: break-word; word-break: normal; padding-right: 4px;">
<div style="margin-left: 0em; margin-top: 1ex; margin-bottom: 1ex;" class="title">
<h1 style="font-size: 115%;  margin-top: 2ex; margin-bottom: 1ex;">HPESBNW05156 rev 1 - Multiple Vulnerabilities in HPE Networking AOS-Swtich (AOS-S)</h1>
</div>
<span style="margin-right: 5px;font-size: 8pt!important" class="metadata-span">Document Subtype:  Security Bulletin</span><span style="margin-right: 5px;font-size: 8pt!important" class="metadata-span">Document ID:  hpesbnw05156en_us</span><span style="margin-right: 5px;font-size: 8pt!important" class="metadata-span">Last Updated:  2026-10-06</span><span style="margin-right: 5px;font-size: 8pt!important" class="metadata-span">Release Date:  2026-10-06</span><span style="margin-right: 5px;font-size: 8pt!important" class="metadata-span">Document Version:  1</span>
<div style="margin-left: 0em; margin-top: 0; margin-bottom: 0;" class="potential_security_impact">
<p style="margin-top: 0; margin-bottom: 5px;">
<b>Potential Security Impact:  </b>
          Remote: Multiple Vulnerabilities
        </p>
</div>
<div style="margin-left: 0em; margin-top: 1ex; margin-bottom: 1ex;" class="source">
<p style="margin-top: 0; margin-bottom: 2ex;">
<b>Source:</b> Hewlett Packard Enterprise, HPE Product Security Response Team</p>
</div>
<div style="margin-left: 0em; margin-top: 2ex; margin-bottom: 2ex;" class="vulnerability.summary">
<h2 style="font-size: 110%;  margin-top: 2ex; margin-bottom: 1ex;">VULNERABILITY SUMMARY</h2>
<p style="margin-top: 0; margin-bottom: 2ex;">
<b>Note:</b> A signed text copy of this document exists at 
<a xmlns:dctm="http://www.documentum.com" href="https://csaf.arubanetworking.hpe.com/2026/hpe_networking_-_hpesbnw05156.txt" title="" target="_blank">hpe_networking_-_hpesbnw05156.txt</a>

</p>
<p style="margin-top: 0; margin-bottom: 2ex;">
<b>Note:</b> A CSAF version of this document exists at 
<a href="https://csaf.arubanetworking.hpe.com/2026/hpe_networking_-_hpesbnw05156.json" title="" target="_blank">hpe_networking_-_hpesbnw05156.json</a>

</p>
<p style="margin-top: 0; margin-bottom: 2ex;">
<b>Summary</b>
</p>
<p style="margin-top: 0; margin-bottom: 2ex;">HPE Networking has released patches for the HPE Networking 
AOS-Switch (AOS-S) that address multiple security vulnerabilities.</p>
<p style="margin-top: 0; margin-bottom: 2ex;">
<b>Affected Products</b>
</p>
<p style="margin-top: 0; margin-bottom: 2ex;">These vulnerabilities affect the following HPE Networking 
AOS-Switch (AOS-S) software versions unless specifically noted 
otherwise in the details section:</p>
<p style="margin-top: 0; margin-bottom: 2ex;">HPE Networking AOS-Switch (AOS-S)</p>
<div style="margin-top: 0; margin-bottom: 2ex;" class="para">
<ul style="margin-top: 0;" class="list">
<li style="margin-top:1ex; margin-bottom:0ex; margin-left:0;">AOS-S 16.11.0031 and below</li>
</ul>
</div>
<p style="margin-top: 0; margin-bottom: 2ex;">
<b>Unffected Products</b>
</p>
<p style="margin-top: 0; margin-bottom: 2ex;">Any other HPE Networking products and software versions 
Not specifically listed above are not affected by these 
vulnerabilities.</p>
<p style="margin-top: 0; margin-bottom: 2ex;">
<b>Workaround</b>
</p>
<p style="margin-top: 0; margin-bottom: 2ex;">To minimize the likelihood of an attacker exploiting these vulnerabilities,
HPE Networking recommends that the CLI and web-based management interfaces
be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall
policies at layer 3 and above along with accounting controls for tracking and 
logging user activities and resource usage.</p>
<p style="margin-top: 0; margin-bottom: 2ex;">
<b>Exploitation and Public Discussion</b>
</p>
<p style="margin-top: 0; margin-bottom: 2ex;">These vulnerabilities were generally discovered by internal
security research at HPE Networking. HPE Networking is not 
aware of any public discussion or exploit code that targets 
the listed vulnerabilities as of the release date of this 
advisory. Customers are strongly urged to patch their 
instances due to the complexity, breadth, and impact of 
these vulnerabilities.</p>
<p style="margin-top: 0; margin-bottom: 2ex;">Please note that due to the size of the Details and 
References sections, these sections have been moved to 
the end of the document to improve readability.</p>
<p style="margin-top: 0; margin-bottom: 2ex;">
<b>Details</b>
</p>
<p style="margin-top: 0; margin-bottom: 2ex;">
<b>Authentication Bypass in the Web Management Interface of AOS-S
(CVE-2026-76742)</b>
</p>
<p style="margin-top: 0; margin-bottom: 2ex;">
<span style="font-family: Courier;white-space: pre;">Authentication bypass vulnerabilities exist in the web management    </span>
<br>
<span style="font-family: Courier;white-space: pre;">interface of AOS-S. Successful exploitation could allow an</span>
<br>
<span style="font-family: Courier;white-space: pre;">unauthenticated remote attacker to gain unauthorized access to </span>
<br>
<span style="font-family: Courier;white-space: pre;">the affected system.</span>
<br>
<span style="font-family: Courier;white-space: pre;"></span>
<br>
<span style="font-family: Courier;white-space: pre;">Internal References: VULN-1429, VULN-1453</span>
<br>
<span style="font-family: Courier;white-space: pre;">Severity: Critical</span>
<br>
<span style="font-family: Courier;white-space: pre;">CVSS v3.1 Base Score: 9.8</span>
<br>
<span style="font-family: Courier;white-space: pre;">CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</span>
<br>
<span style="font-family: Courier;white-space: pre;"></span>
<br>
<span style="font-family: Courier;white-space: pre;">Acknowledgements: Internal security research (HPE Networking).</span>
<br>
</p>
<p style="margin-top: 0; margin-bottom: 2ex;">
<b>Authentication Bypass Vulnerability in the Management Interface 
of AOS-S
(CVE-2026-76743)</b>
</p>
<p style="margin-top: 0; margin-bottom: 2ex;">
<span style="font-family: Courier;white-space: pre;">A vulnerability have been identified in the management interface </span>
<br>
<span style="font-family: Courier;white-space: pre;">of AOS-S that could potentially allow an unauthenticated remote </span>
<br>
<span style="font-family: Courier;white-space: pre;">attacker to circumvent existing authentication controls if </span>
<br>
<span style="font-family: Courier;white-space: pre;">certain preconditions outside of the attacker's control are met.</span>
<br>
<span style="font-family: Courier;white-space: pre;">Successful exploitation could allow an attacker to gain </span>
<br>
<span style="font-family: Courier;white-space: pre;">unauthorized access to the affected system.</span>
<br>
<span style="font-family: Courier;white-space: pre;"></span>
<br>
<span style="font-family: Courier;white-space: pre;">Internal References: VULN-1438</span>
<br>
<span style="font-family: Courier;white-space: pre;">Severity: Critical</span>
<br>
<span style="font-family: Courier;white-space: pre;">CVSS v3.1 Base Score: 9.8</span>
<br>
<span style="font-family: Courier;white-space: pre;">CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</span>
<br>
<span style="font-family: Courier;white-space: pre;"></span>
<br>
<span style="font-family: Courier;white-space: pre;">Acknowledgements: Internal security research (HPE Networking).</span>
<br>
</p>
<p style="margin-top: 0; margin-bottom: 2ex;">
<b>Unauthenticated Buffer Overflow Vulnerabilities lead to Remote 
Code Execution in AOS-S
(CVE-2026-76744)</b>
</p>
<p style="margin-top: 0; margin-bottom: 2ex;">
<span style="font-family: Courier;white-space: pre;">Buffer overflow vulnerabilities exist in the affected interface </span>
<br>
<span style="font-family: Courier;white-space: pre;">of AOS-S. Successful exploitation could allow an unauthenticated </span>
<br>
<span style="font-family: Courier;white-space: pre;">remote attacker to execute arbitrary code.</span>
<br>
<span style="font-family: Courier;white-space: pre;"></span>
<br>
<span style="font-family: Courier;white-space: pre;">Internal References: VULN-594, VULN-595, VULN-596, VULN-597, </span>
<br>
<span style="font-family: Courier;white-space: pre;">                     VULN-598, VULN-623, VULN-630, VULN-1421, </span>
<br>
<span style="font-family: Courier;white-space: pre;">                     VULN-1422, VULN-1424, VULN-1425, VULN-1448, </span>
<br>
<span style="font-family: Courier;white-space: pre;">                     VULN-1451, VULN-1427, VULN-1450, VULN-1419, </span>
<br>
<span style="font-family: Courier;white-space: pre;">                     VULN-1426, VULN-1428, VULN-1437, VULN-1447</span>
<br>
<span style="font-family: Courier;white-space: pre;">Severity: Critical</span>
<br>
<span style="font-family: Courier;white-space: pre;">CVSS v3.1 Base Score: 9.8</span>
<br>
<span style="font-family: Courier;white-space: pre;">CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</span>
<br>
<span style="font-family: Courier;white-space: pre;"></span>
<br>
<span style="font-family: Courier;white-space: pre;">Acknowledgements: Internal security research (HPE Networking).</span>
<br>
</p>
<p style="margin-top: 0; margin-bottom: 2ex;">
<b>Unauthenticated Adjacent Memory Corruption Vulnerabilities Leading 
to Remote Code Execution in AOS-S
(CVE-2026-76745)</b>
</p>
<p style="margin-top: 0; margin-bottom: 2ex;">
<span style="font-family: Courier;white-space: pre;">Memory corruption vulnerabilities exist in AOS-S that are </span>
<br>
<span style="font-family: Courier;white-space: pre;">reachable by an unauthenticated adjacent attacker. Successful </span>
<br>
<span style="font-family: Courier;white-space: pre;">exploitation could allow an attacker to execute arbitrary code.</span>
<br>
<span style="font-family: Courier;white-space: pre;"></span>
<br>
<span style="font-family: Courier;white-space: pre;">Internal References: VULN-1436, VULN-1446, VULN-1435, VULN-1445</span>
<br>
<span style="font-family: Courier;white-space: pre;">Severity: Critical</span>
<br>
<span style="font-family: Courier;white-space: pre;">CVSS v3.1 Base Score: 9.6</span>
<br>
<span style="font-family: Courier;white-space: pre;">CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</span>
<br>
<span style="font-family: Courier;white-space: pre;"></span>
<br>
<span style="font-family: Courier;white-space: pre;">Acknowledgements: Internal security research (HPE Networking).</span>
<br>
</p>
<p style="margin-top: 0; margin-bottom: 2ex;">
<b>Unauthenticated Adjacent Buffer Overflow Vulnerability Leading to 
Information Disclosure in AOS-S
(CVE-2026-76746)</b>
</p>
<p style="margin-top: 0; margin-bottom: 2ex;">
<span style="font-family: Courier;white-space: pre;">An unauthenticated buffer overflow vulnerability exists in AOS-S.</span>
<br>
<span style="font-family: Courier;white-space: pre;">Successful exploitation could allow an unauthenticated adjacent</span>
<br>
<span style="font-family: Courier;white-space: pre;">attacker to expose sensitive memory contents and cause a denial </span>
<br>
<span style="font-family: Courier;white-space: pre;">of service on the affected device.</span>
<br>
<span style="font-family: Courier;white-space: pre;"></span>
<br>
<span style="font-family: Courier;white-space: pre;">Internal References: VULN-1434</span>
<br>
<span style="font-family: Courier;white-space: pre;">Severity: Critical</span>
<br>
<span style="font-family: Courier;white-space: pre;">CVSS v3.1 Base Score: 9.3</span>
<br>
<span style="font-family: Courier;white-space: pre;">CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H</span>
<br>
<span style="font-family: Courier;white-space: pre;"></span>
<br>
<span style="font-family: Courier;white-space: pre;">Acknowledgements: Internal security research (HPE Networking).</span>
<br>
</p>
<p style="margin-top: 0; margin-bottom: 2ex;">
<b>Unauthenticated Buffer Overflow Vulnerabilities lead to Information 
Disclosure in AOS-S
(CVE-2026-76747)</b>
</p>
<p style="margin-top: 0; margin-bottom: 2ex;">
<span style="font-family: Courier;white-space: pre;">Buffer overflow vulnerabilities exist in the affected interface </span>
<br>
<span style="font-family: Courier;white-space: pre;">of AOS-S. Successful exploitation could allow an unauthenticated </span>
<br>
<span style="font-family: Courier;white-space: pre;">remote attacker to expose sensitive memory contents and cause a </span>
<br>
<span style="font-family: Courier;white-space: pre;">denial of service on the device.</span>
<br>
<span style="font-family: Courier;white-space: pre;"></span>
<br>
<span style="font-family: Courier;white-space: pre;">Internal References: VULN-1432, VULN-1440, VULN-1442, VULN-1443,</span>
<br>
<span style="font-family: Courier;white-space: pre;">                     VULN-1430, VULN-1431, VULN-1433, VULN-1439,</span>
<br>
<span style="font-family: Courier;white-space: pre;">                     VULN-1441, VULN-1444, VULN-1420</span>
<br>
<span style="font-family: Courier;white-space: pre;">Severity: Critical</span>
<br>
<span style="font-family: Courier;white-space: pre;">CVSS v3.1 Base Score: 9.1</span>
<br>
<span style="font-family: Courier;white-space: pre;">CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H</span>
<br>
<span style="font-family: Courier;white-space: pre;"></span>
<br>
<span style="font-family: Courier;white-space: pre;">Acknowledgements: Internal security research (HPE Networking).</span>
<br>
</p>
<p style="margin-top: 0; margin-bottom: 2ex;">
<b>Authenticated Privilege Escalation Vulnerability in the API of AOS-S
(CVE-2026-76748)</b>
</p>
<p style="margin-top: 0; margin-bottom: 2ex;">
<span style="font-family: Courier;white-space: pre;">A privilege escalation vulnerability exists in the API of AOS-S.</span>
<br>
<span style="font-family: Courier;white-space: pre;">Successful exploitation could allow an authenticated read-only </span>
<br>
<span style="font-family: Courier;white-space: pre;">user to escalate their privileges and gain administrative access </span>
<br>
<span style="font-family: Courier;white-space: pre;">to the affected system.</span>
<br>
<span style="font-family: Courier;white-space: pre;"></span>
<br>
<span style="font-family: Courier;white-space: pre;">Internal References: VULN-609</span>
<br>
<span style="font-family: Courier;white-space: pre;">Severity: High</span>
<br>
<span style="font-family: Courier;white-space: pre;">CVSS v3.1 Base Score: 8.8</span>
<br>
<span style="font-family: Courier;white-space: pre;">CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</span>
<br>
<span style="font-family: Courier;white-space: pre;"></span>
<br>
<span style="font-family: Courier;white-space: pre;">Acknowledgements: Internal security research (HPE Networking).</span>
<br>
</p>
<p style="margin-top: 0; margin-bottom: 2ex;">
<b>Authenticated Buffer Overflow Vulnerabilities lead to 
Denial-of-Service in AOS-S
(CVE-2026-76741)</b>
</p>
<p style="margin-top: 0; margin-bottom: 2ex;">
<span style="font-family: Courier;white-space: pre;">Buffer overflow vulnerabilities exist in the affected interface </span>
<br>
<span style="font-family: Courier;white-space: pre;">of AOS-S. Successful exploitation could allow an authenticated </span>
<br>
<span style="font-family: Courier;white-space: pre;">remote attacker to cause a denial-of-service condition on the </span>
<br>
<span style="font-family: Courier;white-space: pre;">affected system.</span>
<br>
<span style="font-family: Courier;white-space: pre;"></span>
<br>
<span style="font-family: Courier;white-space: pre;">Internal References: VULN-1423, VULN-1449</span>
<br>
<span style="font-family: Courier;white-space: pre;">Severity: Medium</span>
<br>
<span style="font-family: Courier;white-space: pre;">CVSS v3.1 Base Score: 6.5</span>
<br>
<span style="font-family: Courier;white-space: pre;">CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</span>
<br>
<span style="font-family: Courier;white-space: pre;"></span>
<br>
<span style="font-family: Courier;white-space: pre;">Acknowledgements: Internal security research (HPE Networking).  </span>
<br>
</p>
<p style="margin-top: 0; margin-bottom: 2ex;">
<b>Unauthenticated Sensitive Information Disclosure in AOS-S
(CVE-2026-76749)</b>
</p>
<p style="margin-top: 0; margin-bottom: 2ex;">
<span style="font-family: Courier;white-space: pre;">A sensitive information disclosure vulnerability exists in AOS-S.</span>
<br>
<span style="font-family: Courier;white-space: pre;">Successful exploitation could allow an unauthenticated remote </span>
<br>
<span style="font-family: Courier;white-space: pre;">attacker to access sensitive information.</span>
<br>
<span style="font-family: Courier;white-space: pre;"></span>
<br>
<span style="font-family: Courier;white-space: pre;">Internal References: VULN-1452</span>
<br>
<span style="font-family: Courier;white-space: pre;">Severity: Medium</span>
<br>
<span style="font-family: Courier;white-space: pre;">CVSS v3.1 Base Score: 6.5</span>
<br>
<span style="font-family: Courier;white-space: pre;">CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</span>
<br>
<span style="font-family: Courier;white-space: pre;"></span>
<br>
<span style="font-family: Courier;white-space: pre;">Acknowledgements: Internal security research (HPE Networking).</span>
<br>
</p>
</div>
<div style="margin-left: 0em; margin-top: 0; margin-bottom: 0;" class="reference.number">
<div style="margin-top: 0; margin-bottom: 2ex;" class="para">
<b>References:  </b>
<ul style="margin-top: 0;" class="list">
<li style="margin-top:1ex; margin-bottom:0ex; margin-left:0;">CVE-2026-76742</li>
<li style="margin-top:1ex; margin-bottom:0ex; margin-left:0;">CVE-2026-76743</li>
<li style="margin-top:1ex; margin-bottom:0ex; margin-left:0;">CVE-2026-76744</li>
<li style="margin-top:1ex; margin-bottom:0ex; margin-left:0;">CVE-2026-76745</li>
<li style="margin-top:1ex; margin-bottom:0ex; margin-left:0;">CVE-2026-76746</li>
<li style="margin-top:1ex; margin-bottom:0ex; margin-left:0;">CVE-2026-76747</li>
<li style="margin-top:1ex; margin-bottom:0ex; margin-left:0;">CVE-2026-76748</li>
<li style="margin-top:1ex; margin-bottom:0ex; margin-left:0;">CVE-2026-76741</li>
<li style="margin-top:1ex; margin-bottom:0ex; margin-left:0;">CVE-2026-76749</li>
</ul>
</div>
</div>
<div style="margin-left: 0em; margin-top: 2ex; margin-bottom: 2ex;" class="supported.software.versions">
<h2 style="font-size: 110%;  margin-top: 2ex; margin-bottom: 1ex;">SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.</h2>
<div style="margin-top: 0; margin-bottom: 2ex;" class="para">
<ul style="margin-top: 0;" class="list">
<li style="margin-top:1ex; margin-bottom:0ex; margin-left:0;">Aruba 2530 Switch Series - Please refer to **Vulnerability Summary** for details about affected HPE Networking AOS-Switch (AOS-S) software versions - **Any hardware running the affected software is vulnerable to the vulnerabilities listed in the Vulnerability Summary of this bulletin.**</li>
<li style="margin-top:1ex; margin-bottom:0ex; margin-left:0;">Aruba 2540 Switch Series - Please refer to **Vulnerability Summary** for details about affected HPE Networking AOS-Switch (AOS-S) software versions - **Any hardware running the affected software is vulnerable to the vulnerabilities listed in the Vulnerability Summary of this bulletin.**</li>
<li style="margin-top:1ex; margin-bottom:0ex; margin-left:0;">Aruba 2615 Switch Series - Please refer to **Vulnerability Summary** for details about affected HPE Networking AOS-Switch (AOS-S) software versions - **Any hardware running the affected software is vulnerable to the vulnerabilities listed in the Vulnerability Summary of this bulletin.**</li>
<li style="margin-top:1ex; margin-bottom:0ex; margin-left:0;">Aruba 2620 Switch Series - Please refer to **Vulnerability Summary** for details about affected HPE Networking AOS-Switch (AOS-S) software versions - **Any hardware running the affected software is vulnerable to the vulnerabilities listed in the Vulnerability Summary of this bulletin.**</li>
<li style="margin-top:1ex; margin-bottom:0ex; margin-left:0;">Aruba 2915 Switch Series - Please refer to **Vulnerability Summary** for details about affected HPE Networking AOS-Switch (AOS-S) software versions - **Any hardware running the affected software is vulnerable to the vulnerabilities listed in the Vulnerability Summary of this bulletin.**</li>
<li style="margin-top:1ex; margin-bottom:0ex; margin-left:0;">Aruba 2920 Switch Series - Please refer to **Vulnerability Summary** for details about affected HPE Networking AOS-Switch (AOS-S) software versions - **Any hardware running the affected software is vulnerable to the vulnerabilities listed in the Vulnerability Summary of this bulletin.**</li>
<li style="margin-top:1ex; margin-bottom:0ex; margin-left:0;">Aruba 2930F Switch Series - Please refer to **Vulnerability Summary** for details about affected HPE Networking AOS-Switch (AOS-S) software versions - **Any hardware running the affected software is vulnerable to the vulnerabilities listed in the Vulnerability Summary of this bulletin.**</li>
<li style="margin-top:1ex; margin-bottom:0ex; margin-left:0;">Aruba 2930M Switch Series - Please refer to **Vulnerability Summary** for details about affected HPE Networking AOS-Switch (AOS-S) software versions - **Any hardware running the affected software is vulnerable to the vulnerabilities listed in the Vulnerability Summary of this bulletin.**</li>
<li style="margin-top:1ex; margin-bottom:0ex; margin-left:0;">Aruba 3800 Switch Series - Please refer to **Vulnerability Summary** for details about affected HPE Networking AOS-Switch (AOS-S) software versions - **Any hardware running the affected software is vulnerable to the vulnerabilities listed in the Vulnerability Summary of this bulletin.**</li>
<li style="margin-top:1ex; margin-bottom:0ex; margin-left:0;">Aruba 3810M Switch Series - Please refer to **Vulnerability Summary** for details about affected HPE Networking AOS-Switch (AOS-S) software versions - **Any hardware running the affected software is vulnerable to the vulnerabilities listed in the Vulnerability Summary of this bulletin.**</li>
<li style="margin-top:1ex; margin-bottom:0ex; margin-left:0;">Aruba 5400 zl Switch Series - Please refer to **Vulnerability Summary** for details about affected HPE Networking AOS-Switch (AOS-S) software versions - **Any hardware running the affected software is vulnerable to the vulnerabilities listed in the Vulnerability Summary of this bulletin.**</li>
<li style="margin-top:1ex; margin-bottom:0ex; margin-left:0;">Aruba 5400R zl2 Switch Series - Please refer to **Vulnerability Summary** for details about affected HPE Networking AOS-Switch (AOS-S) software versions - **Any hardware running the affected software is vulnerable to the vulnerabilities listed in the Vulnerability Summary of this bulletin.**</li>
<li style="margin-top:1ex; margin-bottom:0ex; margin-left:0;">Aruba 6300 Switch Series - Please refer to **Vulnerability Summary** for details about affected HPE Networking AOS-Switch (AOS-S) software versions - **Any hardware running the affected software is vulnerable to the vulnerabilities listed in the Vulnerability Summary of this bulletin.**</li>
<li style="margin-top:1ex; margin-bottom:0ex; margin-left:0;">Aruba 6400 Switch Series - Please refer to **Vulnerability Summary** for details about affected HPE Networking AOS-Switch (AOS-S) software versions - **Any hardware running the affected software is vulnerable to the vulnerabilities listed in the Vulnerability Summary of this bulletin.**</li>
<li style="margin-top:1ex; margin-bottom:0ex; margin-left:0;">Aruba 8320 Switch Series - Please refer to **Vulnerability Summary** for details about affected HPE Networking AOS-Switch (AOS-S) software versions - **Any hardware running the affected software is vulnerable to the vulnerabilities listed in the Vulnerability Summary of this bulletin.**</li>
<li style="margin-top:1ex; margin-bottom:0ex; margin-left:0;">Aruba 8325 Switch Series - Please refer to **Vulnerability Summary** for details about affected HPE Networking AOS-Switch (AOS-S) software versions - **Any hardware running the affected software is vulnerable to the vulnerabilities listed in the Vulnerability Summary of this bulletin.**</li>
<li style="margin-top:1ex; margin-bottom:0ex; margin-left:0;">Aruba 8400 Switch Series - Please refer to **Vulnerability Summary** for details about affected HPE Networking AOS-Switch (AOS-S) software versions - **Any hardware running the affected software is vulnerable to the vulnerabilities listed in the Vulnerability Summary of this bulletin.**</li>
</ul>
</div>
</div>
<div style="margin-left: 0em; margin-top: 1ex; margin-bottom: 1ex;" class="background">
<h2 style="font-size: 110%;  margin-top: 2ex; margin-bottom: 1ex;">BACKGROUND</h2>
</div>
<div style="margin-left: 0em; margin-top: 1ex; margin-bottom: 1ex;" class="background.text">
<div style="margin-top: 0; margin-bottom: 2ex;" class="para">
          HPE calculates CVSS using CVSS Version 3.1. If the score is provided from NIST, we will display Version 3.1 as provided from NVD.<table style="font-size: '100%'; width: 100%;" cellspacing="0" cellpadding="4" border="0" class="ods_si_table_bordered">
<thead valign="bottom" style="">
<tr class="theme">
<th style="text-align:left;" rowspan="1">
<div class="para">Reference</div>
</th><th style="text-align:left;">
<div class="para">V3 Vector</div>
</th><th style="text-align:left;">
<div class="para">V3 Base Score</div>
</th>
</tr>
</thead>
<tbody valign="top">
<tr class="ods_si_tr_odd">
<td style="padding-top:5px;padding-bottom:5px;padding-right:10px;" rowspan="1">
<div class="para">CVE-2026-76741</div>
</td><td style="padding-top:5px;padding-bottom:5px;padding-right:10px;" rowspan="1">
<div class="para">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</div>
</td><td style="padding-top:5px;padding-bottom:5px;padding-right:10px;" rowspan="1">
<div class="para">6.5</div>
</td>
</tr>
<tr class="ods_si_tr_even">
<td style="padding-top:5px;padding-bottom:5px;padding-right:10px;" rowspan="1">
<div class="para">CVE-2026-76742</div>
</td><td style="padding-top:5px;padding-bottom:5px;padding-right:10px;" rowspan="1">
<div class="para">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</div>
</td><td style="padding-top:5px;padding-bottom:5px;padding-right:10px;" rowspan="1">
<div class="para">9.8</div>
</td>
</tr>
<tr class="ods_si_tr_odd">
<td style="padding-top:5px;padding-bottom:5px;padding-right:10px;" rowspan="1">
<div class="para">CVE-2026-76743</div>
</td><td style="padding-top:5px;padding-bottom:5px;padding-right:10px;" rowspan="1">
<div class="para">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</div>
</td><td style="padding-top:5px;padding-bottom:5px;padding-right:10px;" rowspan="1">
<div class="para">9.8</div>
</td>
</tr>
<tr class="ods_si_tr_even">
<td style="padding-top:5px;padding-bottom:5px;padding-right:10px;" rowspan="1">
<div class="para">CVE-2026-76744</div>
</td><td style="padding-top:5px;padding-bottom:5px;padding-right:10px;" rowspan="1">
<div class="para">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</div>
</td><td style="padding-top:5px;padding-bottom:5px;padding-right:10px;" rowspan="1">
<div class="para">9.8</div>
</td>
</tr>
<tr class="ods_si_tr_odd">
<td style="padding-top:5px;padding-bottom:5px;padding-right:10px;" rowspan="1">
<div class="para">CVE-2026-76745</div>
</td><td style="padding-top:5px;padding-bottom:5px;padding-right:10px;" rowspan="1">
<div class="para">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</div>
</td><td style="padding-top:5px;padding-bottom:5px;padding-right:10px;" rowspan="1">
<div class="para">9.6</div>
</td>
</tr>
<tr class="ods_si_tr_even">
<td style="padding-top:5px;padding-bottom:5px;padding-right:10px;" rowspan="1">
<div class="para">CVE-2026-76746</div>
</td><td style="padding-top:5px;padding-bottom:5px;padding-right:10px;" rowspan="1">
<div class="para">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H</div>
</td><td style="padding-top:5px;padding-bottom:5px;padding-right:10px;" rowspan="1">
<div class="para">9.3</div>
</td>
</tr>
<tr class="ods_si_tr_odd">
<td style="padding-top:5px;padding-bottom:5px;padding-right:10px;" rowspan="1">
<div class="para">CVE-2026-76747</div>
</td><td style="padding-top:5px;padding-bottom:5px;padding-right:10px;" rowspan="1">
<div class="para">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H</div>
</td><td style="padding-top:5px;padding-bottom:5px;padding-right:10px;" rowspan="1">
<div class="para">9.1</div>
</td>
</tr>
<tr class="ods_si_tr_even">
<td style="padding-top:5px;padding-bottom:5px;padding-right:10px;" rowspan="1">
<div class="para">CVE-2026-76748</div>
</td><td style="padding-top:5px;padding-bottom:5px;padding-right:10px;" rowspan="1">
<div class="para">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</div>
</td><td style="padding-top:5px;padding-bottom:5px;padding-right:10px;" rowspan="1">
<div class="para">8.8</div>
</td>
</tr>
<tr class="ods_si_tr_odd">
<td style="padding-top:5px;padding-bottom:5px;padding-right:10px;" rowspan="1">
<div class="para">CVE-2026-76749</div>
</td><td style="padding-top:5px;padding-bottom:5px;padding-right:10px;" rowspan="1">
<div class="para">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</div>
</td><td style="padding-top:5px;padding-bottom:5px;padding-right:10px;" rowspan="1">
<div class="para">6.5</div>
</td>
</tr>
</tbody>
</table>
          Information on CVSS is documented in HPE Customer Notice: HPSN-2008-002
        </div>
<p style="margin-top: 0; margin-bottom: 2ex;">Please refer to the <b>Vulnerability Summary</b> section for acknowledgements of reported vulnerabilities.</p>
</div>
<div style="margin-left: 0em; margin-top: 2ex; margin-bottom: 2ex;" class="resolution">
<h2 style="font-size: 110%;  margin-top: 2ex; margin-bottom: 1ex;">RESOLUTION</h2>
<p style="margin-top: 0; margin-bottom: 2ex;">To address the vulnerabilities described in the Details 
Section, HPE Networking recommends upgrading the HPE 
Networking AOS-Switch (AOS-S) products to the following 
software versions (as applicable):</p>
<div style="margin-top: 0; margin-bottom: 2ex;" class="para">
<ul style="margin-top: 0;" class="list">
<li style="margin-top:1ex; margin-bottom:0ex; margin-left:0;">AOS-S 16.11.0032 and above</li>
</ul>
</div>
<p style="margin-top: 0; margin-bottom: 2ex;">Software versions with resolution/fixes for the vulnerabilities
covered above can be downloaded from the HPE Networking
Support Portal at: 
<a href="https://networkingsupport.hpe.com" title="" target="_blank">https://networkingsupport.hpe.com</a>

</p>
<p style="margin-top: 0; margin-bottom: 2ex;">
<b>NOTE</b>: Product software versions that have reached End of
Maintenance (EoM) are presumed to be affected by the
vulnerabilities unless explicitly stated otherwise and are
not covered by this security advisory. For deployments
running software versions that are past End of Support
(EoS), HPE Networking has not assessed exposure to the
vulnerabilities referenced in this advisory. As a result,
such installations should be considered potentially impacted
by the listed CVE. Customers are strongly encouraged to
upgrade to a supported software release to ensure proper
evaluation and remediation.</p>
</div>
<div style="margin-left: 0em; margin-top: 1ex; margin-bottom: 1ex;" class="resolution">
<p style="margin-top: 0; margin-bottom: 2ex;">
<b>HISTORY</b>
<br>
          Version:1 (rev.1) - 6 October 2026 Initial release
        </p>
</div>
<div style="margin-left: 0em; margin-top: 1ex; margin-bottom: 1ex;" class="resolution">
<p style="margin-top: 0; margin-bottom: 2ex;">
<b>Third Party Security Patches:</b> Third party security patches that are to be installed on systems running Hewlett Packard Enterprise (HPE) software products should be applied in accordance with the customer's patch management policy.
  </p>
<p style="margin-top: 0; margin-bottom: 2ex;">
<b>Support:</b> For issues about implementing the recommendations of this Security Bulletin, contact normal HPE Services support channel. For other issues about the content of this Security Bulletin, send e-mail to  security-alert@hpe.com.
  </p>
<div style="margin-top: 0; margin-bottom: 2ex;" class="para">
<b>Report:</b> To report a potential security vulnerability for any HPE supported product:
    <ul style="margin-top: 0;" class="list">
<li style="margin-top:1ex; margin-bottom:0ex; margin-left:0;">
<p style="margin-top: 0; margin-bottom: 2ex;">
          Web Form: 
<a href="https://www.hpe.com/info/report-security-vulnerability" title="" target="_blank">https://www.hpe.com/info/report-security-vulnerability</a>

</p>
</li>
<li style="margin-top:1ex; margin-bottom:0ex; margin-left:0;">
<p style="margin-top: 0; margin-bottom: 2ex;">
          Email: security-alert@hpe.com
        </p>
</li>
<li style="margin-top:1ex; margin-bottom:0ex; margin-left:0;">
<p style="margin-top: 0; margin-bottom: 2ex;">

<a href="http://www.hpe.com/support/security-response-policy" title="" target="_blank">Hewlett Packard Enterprise Product Security Response Policy</a>

</p>
</li>
</ul>
</div>
<p style="margin-top: 0; margin-bottom: 2ex;">
<b>Subscribe: </b>To initiate a subscription to receive future HPE Security Bulletin alerts via Email: 
<a href="http://www.hpe.com/support/Subscriber_Choice" title="" target="_blank">http://www.hpe.com/support/Subscriber_Choice</a>

</p>
<p style="margin-top: 0; margin-bottom: 2ex;">
<b>Security Bulletin Archive: </b> A list of recently released Security Bulletins is available here: 
<a href="http://www.hpe.com/support/Security_Bulletin_Archive" title="" target="_blank">http://www.hpe.com/support/Security_Bulletin_Archive</a>

</p>
</div>
<div style="margin-left: 0em; margin-top: 1ex; margin-bottom: 1ex;" class="subscribe">
<p style="margin-top: 0; margin-bottom: 2ex;">System management and security procedures must be reviewed frequently to maintain system integrity. HPE is continually reviewing and enhancing the security features of software products to provide customers with current secure solutions.<br>
</p>
<p style="margin-top: 0; margin-bottom: 2ex;">"HPE is broadly distributing this Security Bulletin in order to bring to the attention of users of the affected HPE products the important security information contained in this Bulletin. HPE recommends that all users determine the applicability of this information to their individual situations and take appropriate action. 
			 HPE does not warrant that this information is necessarily accurate or complete for all user situations 
			 and, consequently, HPE will not be responsible for any damages resulting from user's use or disregard 
			 of the information provided in this Bulletin. To the extent permitted by law, HPE disclaims all warranties, 
			 either express or implied, including the warranties of merchantability and fitness for a particular 
			 purpose, title and non-infringement."</p>
</div>
<div style="margin-left: 0em; margin-top: 1ex; margin-bottom: 1ex;" class="copyright.notice">
<div style=" margin-top: 0; margin-bottom: 2ex; font-size: 100%; text-align: center;" class="para">&copy;Copyright 2026 Hewlett Packard Enterprise Development LP</div>
<div style=" margin-top: 0; margin-bottom: 0; font-size: 100%; text-align: left;" class="para">Hewlett Packard Enterprise Development shall not be liable for technical or editorial errors or omissions contained herein. The information provided is provided "as is" without warranty of any kind. To the extent permitted by law, neither HPE nor its affiliates, subcontractors or suppliers will be liable for incidental, special or consequential damages including downtime cost; lost profits; damages relating to the procurement of substitute products or services; or damages for loss of data, or software restoration. The information in this document is subject to change without notice. Hewlett Packard Enterprise Development and the names of Hewlett Packard Enterprise Development products referenced herein are trademarks of Hewlett Packard Enterprise Development in the United States and other countries. Other product and company names mentioned herein may be trademarks of their respective owners.</div>
</div>
</td>
</tr>
</table>
</div>
</body>
</html>
