Vendor
Arubanetworks vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 52 vulnerabilities in Arubanetworks: 1 in the last 7 days and 52 in the last 90 days, 6 of them critical and 0 exploited in the wild. The most recent, CVE-2026-76708, was published on 22 September 2026. 1 technology has a page of its own.
- Last 7 days
- 1
- Last 90 days
- 52
- Critical, all time
- 6
- Exploited in the wild
- 0
About Arubanetworks
Aruba Networks is a subsidiary of Hewlett Packard Enterprise that develops networking equipment, including wireless access points and switches.
Arubanetworks technologies
Latest Arubanetworks vulnerabilities
- CVE-2026-76708: HPE Analytics and Location Engine default credentialscriticalCVSS 9.8EPSS 0.6%
- CVE-2026-76658: HPE Networking Fabric Composer SSH daemon auth bypasscriticalCVSS 10EPSS 0.8%
- CVE-2026-76657: HPE Networking Fabric Composer API authentication bypasscriticalCVSS 10EPSS 0.8%
- CVE-2026-73748: HPE Networking Fabric Composer information disclosure in management interfacelowCVSS 2.2EPSS 0.2%
- CVE-2026-73747: HPE Networking Fabric Composer privilege escalationlowCVSS 2.5EPSS 0.1%
- CVE-2026-73746: HPE Networking Fabric Composer API denial of servicelowCVSS 3.1EPSS 0.3%
- CVE-2026-73745: HPE Networking Fabric Composer API information disclosurelowCVSS 3.1EPSS 0.3%
- CVE-2026-73744: HPE Networking Fabric Composer denial of service in management interfacelowCVSS 3.5EPSS 0.3%
- CVE-2026-73743: HPE Networking Fabric Composer information disclosure in web interfacelowCVSS 3.7EPSS 0.2%
- CVE-2026-73742: HPE Networking Fabric Composer API spoofing in request attributionmediumCVSS 4.3EPSS 0.3%
- CVE-2026-73741: HPE Networking Fabric Composer API privilege escalationmediumCVSS 4.3EPSS 0.3%
- CVE-2026-73740: HPE Networking Fabric Composer privilege escalationmediumCVSS 4.4EPSS 0.1%
- CVE-2026-73739: HPE Networking Fabric Composer cleartext sensitive information disclosure in APImediumCVSS 4.4EPSS 0.2%
- CVE-2026-73738: HPE Networking Fabric Composer information disclosure in underlying OSmediumCVSS 4.7EPSS 0.1%
- CVE-2026-73737: HPE Networking Fabric Composer unauthenticated path traversal in APImediumCVSS 4.8EPSS 0.2%
- CVE-2026-73736: HPE Networking Fabric Composer path traversal in web interfacemediumCVSS 5.3EPSS 0.4%
- CVE-2026-73735: HPE Networking Fabric Composer privilege escalation in APImediumCVSS 5.4EPSS 0.3%
- CVE-2026-73734: HPE Networking Fabric Composer open redirect in management interfacemediumCVSS 5.4EPSS 0.3%
- CVE-2026-73733: HPE Networking Fabric Composer API authentication bypassmediumCVSS 5.4EPSS 0.3%
- CVE-2026-73732: HPE Networking Fabric Composer privilege escalation via OS vulnerabilitymediumCVSS 5.6EPSS 0.1%
- CVE-2026-73731: HPE Networking Fabric Composer reflected XSS in web management interfacemediumCVSS 6.1EPSS 0.3%
- CVE-2026-73730: HPE Networking Fabric Composer API privilege escalationmediumCVSS 6.5EPSS 0.3%
- CVE-2026-73729: HPE Networking Fabric Composer privilege escalation in underlying OSmediumCVSS 6.5EPSS 0.1%
- CVE-2026-73728: HPE Networking Fabric Composer API denial of servicemediumCVSS 6.5EPSS 0.4%
- CVE-2026-73727: HPE Networking Fabric Composer API privilege escalationmediumCVSS 6.5EPSS 0.3%
Most severe Arubanetworks vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-76658: HPE Networking Fabric Composer SSH daemon auth bypasscriticalCVSS 10EPSS 0.8%
- CVE-2026-76657: HPE Networking Fabric Composer API authentication bypasscriticalCVSS 10EPSS 0.8%
- CVE-2026-76708: HPE Analytics and Location Engine default credentialscriticalCVSS 9.8EPSS 0.6%
- CVE-2026-19766: HPE Networking Fabric Composer authentication bypass in OScriticalCVSS 9.6EPSS 0.3%
- CVE-2026-73701: HPE Networking Fabric Composer unauthenticated remote code executioncriticalCVSS 9EPSS 0.7%
- CVE-2026-73700: HPE Networking Fabric Composer stored cross-site scripting in management interfacecriticalCVSS 9EPSS 0.4%
- CVE-2026-73705: HPE Networking Fabric Composer arbitrary file write in APIhighCVSS 8.8EPSS 0.6%
- CVE-2026-73704: HPE Networking Fabric Composer command sanitization bypass in APIhighCVSS 8.8EPSS 0.5%
- CVE-2026-73702: HPE Networking Fabric Composer privilege escalation in APIhighCVSS 8.8EPSS 0.4%
- CVE-2026-73703: HPE Networking Fabric Composer stored XSS in web management interfacehighCVSS 8.8EPSS 0.3%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 51 | 5 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 1 | 1 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/arubanetworks.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Arubanetworks vulnerabilities", https://junglewise.ai/threats/vendors/arubanetworks, 26 September 2026.