TL;DR
HPE Networking has patched nine HPE AOS-Switch vulnerabilities, and six of them rate Critical. The worst let an unauthenticated attacker run code or bypass login on the switch. Admins should upgrade to AOS-S 16.11.0032 or later.
- Total: 9 CVEs
- Severity: 6 Critical · 1 High · 2 Medium
- Actively exploited: None confirmed
- Highest severity: 9.8 (Critical · CVSSv3) — CVE-2026-76744
- Action: Apply the latest security updates now
Turn matching CVEs into GitHub Issues automatically — no copy-pasting, no duplicates.
Try Team free for 14 daysNotable CVEs
| CVE | CVSS (CVSSv3) | Type | Status |
|---|---|---|---|
| CVE-2026-76744 | 9.8 | Unauthenticated Buffer Overflow lead to Remote Code Execution in AOS-S | Not exploited |
| CVE-2026-76742 | 9.8 | Authentication Bypass in the Web Management Interface of AOS-S | Not exploited |
| CVE-2026-76743 | 9.8 | Authentication Bypass in the Management Interface of AOS-S | Not exploited |
| CVE-2026-76745 | 9.6 | Unauthenticated Adjacent Memory Corruption Leading to Remote Code Execution in AOS-S | Not exploited |
| CVE-2026-76746 | 9.3 | Unauthenticated Adjacent Buffer Overflow Leading to Information Disclosure in AOS-S | Not exploited |
| CVE-2026-76747 | 9.1 | Unauthenticated Buffer Overflow lead to Information Disclosure in AOS-S | Not exploited |
| CVE-2026-76748 | 8.8 | Authenticated Privilege Escalation in the API of AOS-S | Not exploited |
| CVE-2026-76741 | 6.5 | Authenticated Buffer Overflow lead to Denial-of-Service in AOS-S | Not exploited |
Why It Matters
AOS-Switch (AOS-S) runs on HPE Aruba campus and branch switches. These devices sit at the core of many enterprise networks. As a result, an attacker who takes over a switch could watch or redirect traffic.
The bulletin pairs high severity with a wide spread of bugs. HPE says “customers are strongly urged to patch their instances due to the complexity, breadth, and impact of these vulnerabilities.” Its internal security research found the issues.
For now, there is no sign of attacks. HPE “is not aware of any public discussion or exploit code that targets the listed vulnerabilities as of the release date of this advisory.”
How the Attacks Work
Remote Code Execution
The most serious entry is CVE-2026-76744, rated 9.8. It groups 20 buffer overflow bugs in an affected interface. Per HPE, success “could allow an unauthenticated remote attacker to execute arbitrary code.” Meanwhile, CVE-2026-76745 (9.6) covers memory corruption bugs. An attacker on an adjacent network can use them to run code without logging in.
Authentication Bypass
Two more HPE AOS-Switch vulnerabilities target login controls. CVE-2026-76742 (9.8) affects the web management interface. It could let an unauthenticated attacker “gain unauthorized access to the affected system.” CVE-2026-76743 (9.8) is similar. However, it only works if “certain preconditions outside of the attacker’s control are met.”
Memory Leaks and Other Bugs
CVE-2026-76746 (9.3) and CVE-2026-76747 (9.1) are buffer overflows. They can expose memory contents and crash the device. Next, CVE-2026-76748 (8.8) lets a read-only API user gain admin rights. Finally, CVE-2026-76741 causes denial of service, and CVE-2026-76749 leaks sensitive data.
Affected Versions
The bulletin lists AOS-S 16.11.0031 and below as affected. All nine flaws share the same fixed release, so one upgrade closes every issue. Six of them need no login at all, which widens the pool of possible attackers. HPE also presumes that end-of-maintenance releases are vulnerable, though it does not cover them. In addition, it has not assessed releases past end of support.
Patch and Mitigation Steps
First, upgrade to AOS-S 16.11.0032 or later. The fixed build is available from the HPE Networking Support Portal.
If you cannot patch right away, restrict management access. HPE recommends placing the CLI and web interfaces on “a dedicated layer 2 segment/VLAN” or behind firewall policies. It also advises logging user activity. Since several of these HPE AOS-Switch vulnerabilities need no login, treat the update as urgent, even without confirmed attacks.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!