HPE Networking AOS-Switch bulletin HPESBNW05156: nine flaws in AOS-S 16.11.0031 and earlier, including unauthenticated management-interface authentication bypasses (CVE-2026-76742, CVE-2026-76743) and buffer overflows leading to code execution (CVE-2026-76744), all CVSS 9.8; upgrade to 16.11.0032
HPE published security bulletin HPESBNW05156 on 6 October 2026 for HPE Networking AOS-Switch (AOS-S), the operating system on the former Aruba campus and access switches. It covers nine vulnerabilities in AOS-S 16.11.0031 and earlier, mostly found by HPE's own researchers. Three are rated 9.8 and need no login: CVE-2026-76742, an authentication bypass in the web management interface; CVE-2026-76743, an authentication bypass in the management interface that depends on conditions outside the attacker's control; and CVE-2026-76744, a group of buffer overflows that can let a remote attacker run code. Others include memory corruption reachable from an adjacent network that can lead to code execution (CVE-2026-76745, 9.6), adjacent and remote buffer overflows that leak information (CVE-2026-76746, 9.3; CVE-2026-76747, 9.1), privilege escalation through the API for a logged-in user (CVE-2026-76748, 8.8), and two 6.5-rated issues covering denial of service and information disclosure (CVE-2026-76741, CVE-2026-76749). HPE says it knows of no public discussion or exploit code, but urges customers to patch because of how broad and serious the set is. Versions past End of Maintenance should be treated as affected. Primary: HPE security bulletin.
- Product
- HPE Networking AOS-Switch (AOS-S) switch software
- Versions
- AOS-S 16.11.0031 and earlier (fixed 16.11.0032 and later); versions past End of Maintenance presumed affected
- CVSS
- Critical (CVE-2026-76742, CVE-2026-76743, CVE-2026-76744, CVSS 3.1, HPE); others 6.5 to 9.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- Upgrade AOS-S to 16.11.0032 or later from the HPE Networking Support Portal. Until then, follow HPE's workaround: keep the CLI and web management interfaces on a dedicated management VLAN or behind firewall rules, never reachable from user or internet networks, and turn on accounting and logging for management access. Replace switches whose software is past End of Maintenance.
Primary: HPE — HPESBNW05156 rev 1: Multiple Vulnerabilities in HPE Networking AOS-Switch (AOS-S) (6 Oct 2026) · Vendor: CVE record — CVE-2026-76742 (HPE CNA, published 6 Oct 2026) · CVE: CVE-2026-76742, CVE-2026-76743, CVE-2026-76744, CVE-2026-76745, CVE-2026-76746, CVE-2026-76747, CVE-2026-76748, CVE-2026-76741, CVE-2026-76749
