HPE Aruba Networking Private 5G Core shipped fixes for multiple vulnerabilities affecting versions 1.24.3.0 through 1.24.3.3 that could allow remote, unauthenticated attackers to compromise private 5G core management functions. The most severe issue, CVE-2026-23595 (CVSS 8.8), is an authentication bypass in the application API that can allow an attacker to create a new administrative account without credentials, enabling full administrative control, configuration changes, and potential access to or manipulation of sensitive data within the private 5G core environment.
Additional flaws reported alongside the auth bypass include an unauthenticated management-API condition that can trigger service restarts (CVE-2026-23596), creating a denial-of-service risk, and information disclosure issues (CVE-2026-23597 and CVE-2026-23598) that can expose details such as user accounts and roles. The Canadian Centre for Cyber Security also issued an alert referencing HPE’s bulletin (HPESBNW05002 rev.1) and urged organizations running affected Private 5G Core versions to apply vendor updates; other Canadian Centre advisories in the same period (Apple, Chrome, Drupal, Intel, Fortinet, Siemens, Dell, CISA ICS, IBM, Red Hat, and a broader HPE roundup) are separate patch notifications and not specific to the Aruba Private 5G Core issue.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security issued alert AV26-110 referencing HPE's advisory and directed users and administrators to review the bulletin and apply the necessary updates. The notice highlighted the affected versions and pointed readers to HPE's Security Bulletin Library for more details.
On February 10, 2026, HPE published security bulletin HPESBNW05002 rev.1 covering multiple vulnerabilities in HPE Aruba Networking Private 5G Core, including CVE-2026-23595 through CVE-2026-23598. HPE released version 1.25.1.0 to remediate the flaws and advised customers running 1.24.3.x to upgrade.
The Communications Security Establishment discovered four vulnerabilities in HPE Aruba Networking Private 5G Core that could enable authentication bypass, administrative takeover, denial of service, and information disclosure. The issues affected versions 1.24.3.0 through 1.24.3.3.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.