Vulnerability
Published 2026-10-06
Verified 2026-10-07

HPE Networking AOS-Switch bulletin HPESBNW05156: nine flaws in AOS-S 16.11.0031 and earlier, including unauthenticated management-interface authentication bypasses (CVE-2026-76742, CVE-2026-76743) and buffer overflows leading to code execution (CVE-2026-76744), all CVSS 9.8; upgrade to 16.11.0032

HPE published security bulletin HPESBNW05156 on 6 October 2026 for HPE Networking AOS-Switch (AOS-S), the operating system on the former Aruba campus and access switches. It covers nine vulnerabilities in AOS-S 16.11.0031 and earlier, mostly found by HPE's own researchers. Three are rated 9.8 and need no login: CVE-2026-76742, an authentication bypass in the web management interface; CVE-2026-76743, an authentication bypass in the management interface that depends on conditions outside the attacker's control; and CVE-2026-76744, a group of buffer overflows that can let a remote attacker run code. Others include memory corruption reachable from an adjacent network that can lead to code execution (CVE-2026-76745, 9.6), adjacent and remote buffer overflows that leak information (CVE-2026-76746, 9.3; CVE-2026-76747, 9.1), privilege escalation through the API for a logged-in user (CVE-2026-76748, 8.8), and two 6.5-rated issues covering denial of service and information disclosure (CVE-2026-76741, CVE-2026-76749). HPE says it knows of no public discussion or exploit code, but urges customers to patch because of how broad and serious the set is. Versions past End of Maintenance should be treated as affected. Primary: HPE security bulletin.

Product
HPE Networking AOS-Switch (AOS-S) switch software
Versions
AOS-S 16.11.0031 and earlier (fixed 16.11.0032 and later); versions past End of Maintenance presumed affected
CVSS
Critical (CVE-2026-76742, CVE-2026-76743, CVE-2026-76744, CVSS 3.1, HPE); others 6.5 to 9.6
Exploited in Australia?
unknown
Patch to
Upgrade AOS-S to 16.11.0032 or later from the HPE Networking Support Portal. Until then, follow HPE's workaround: keep the CLI and web management interfaces on a dedicated management VLAN or behind firewall rules, never reachable from user or internet networks, and turn on accounting and logging for management access. Replace switches whose software is past End of Maintenance.

Primary: HPE — HPESBNW05156 rev 1: Multiple Vulnerabilities in HPE Networking AOS-Switch (AOS-S) (6 Oct 2026) · Vendor: CVE record — CVE-2026-76742 (HPE CNA, published 6 Oct 2026) · CVE: CVE-2026-76742, CVE-2026-76743, CVE-2026-76744, CVE-2026-76745, CVE-2026-76746, CVE-2026-76747, CVE-2026-76748, CVE-2026-76741, CVE-2026-76749

vulnerabilities network