{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/aos-cx--10.10.1181/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AOS-CX (10.13.x \u003c 10.13.1190)","AOS-CX (10.16.x \u003c 10.16.1060)","AOS-CX (10.17.x \u003c 10.17.1030)","AOS-CX (10.18.x \u003c 10.18.1002)","AOS-CX (\u003c 10.10.1181)","Fabric Composer (\u003c 7.3.4)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","networking","infrastructure"],"_cs_type":"advisory","_cs_vendors":["HPE"],"content_html":"\u003cp\u003eOn September 1, 2026, HPE Aruba Networking published two security bulletins (HPESBNW05133 and HPESBNW05134) detailing a large volume of vulnerabilities affecting the AOS-CX network operating system and Fabric Composer. These vulnerabilities encompass a broad spectrum of impact, including remote code execution (RCE), privilege escalation, denial of service (DoS), SQL injection (SQLi), cross-site scripting (XSS), server-side request forgery (SSRF), and cross-site request forgery (CSRF).\u003c/p\u003e\n\u003cp\u003eThe scope of the affected software is significant, covering multiple major release trains of AOS-CX, including versions 10.13.x, 10.16.x, 10.17.x, 10.18.x, and legacy 10.10.x. Fabric Composer versions earlier than 7.3.4 are also impacted. Given the critical nature of these services within enterprise network infrastructure, these vulnerabilities present a high risk for unauthorized network control and data exfiltration. Defenders must verify the current firmware versions of all deployed Aruba switches and controllers against the patched versions identified in the vendor bulletins.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities can lead to a complete compromise of the underlying networking equipment. An attacker could potentially bypass security policies, exfiltrate sensitive data passing through the network, or disrupt business operations via denial-of-service attacks. The broad range of vulnerability types (SQLi, XSS, SSRF) implies that internal web interfaces and management APIs are significant vectors. Given the position of Aruba switches at the edge and core of corporate networks, these flaws pose a systemic risk to enterprise network integrity.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInventory all Aruba AOS-CX and Fabric Composer appliances across the environment.\u003c/li\u003e\n\u003cli\u003ePrioritize patching devices running the legacy AOS-CX 10.10.x train, as these systems have reached end-of-maintenance and are receiving critical-only updates.\u003c/li\u003e\n\u003cli\u003eApply the security patches provided in HPE bulletins HPESBNW05133 and HPESBNW05134 immediately.\u003c/li\u003e\n\u003cli\u003eRestrict access to management interfaces (HTTPS/SSH/API) to trusted administrative subnets only.\u003c/li\u003e\n\u003cli\u003eEnable robust logging on management interfaces to detect abnormal access patterns or unexpected HTTP/API requests consistent with web injection attempts.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-02T18:02:32Z","date_published":"2026-09-02T18:02:32Z","id":"https://feed.craftedsignal.io/briefs/2026-09-hpe-aruba-vulns/","summary":"HPE has disclosed a wide range of vulnerabilities across AOS-CX and Fabric Composer, including RCE, privilege escalation, and DoS flaws, impacting numerous versions of the network operating system.","title":"Multiple Critical Vulnerabilities in HPE Aruba Networking Products","url":"https://feed.craftedsignal.io/briefs/2026-09-hpe-aruba-vulns/"}],"language":"en","title":"CraftedSignal Threat Feed - AOS-CX (\u003c 10.10.1181)","version":"https://jsonfeed.org/version/1.1"}