Aruba Security Updates – 11 March 2026

HPE Aruba has released security updates to fix several vulnerabilities across multiple HPE Aruba products.

The addressed vulnerabilities could allow the attacker to bypass security restrictions, obtain sensitive information, perform denial-of-service and cross-site scripting attacks, gain elevated privileges, or execute arbitrary code and gain access to the affected systems.

Sample of the addressed vulnerabilities:

1. HPE Aruba Networking AOS-CX Authentication Bypass Vulnerability (CVE- 2026-23813):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access

2. HPE Aruba Networking Clear Pass Policy Manager OnGuard Software for Linux local Privilege Escalation Vulnerability (CVE-2026-23599):

  • CVSS: 7.8
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Gain Privileges
Vulnerabilities
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Aruba Security Advisory

References