HPE issued a security bulletin (HPESBNW05026) for multiple vulnerabilities in HPE Aruba Networking wireless operating systems affecting Mobility Conductors, Controllers, Gateways, and Access Points running AOS-8 and AOS-10. The issues span several impact categories including spoofing, information disclosure, security restriction bypass, and denial of service, and are tracked as CVE-2026-00212, CVE-2026-00213, CVE-2026-00214, CVE-2026-00215, CVE-2026-00216, and CVE-2026-00219.
Advisories highlight that affected versions include AOS-8 (e.g., 8.10.0.21 and below; 8.12.0.6 and below; 8.13.1.1 and below) and AOS-10 (e.g., 10.4.1.10 and below; 10.7.2.2 and below; 10.8.0.0 and below), and that end-of-maintenance (EoM) trains are not addressed by vendor fixes (e.g., AOS-10.3/10.5/10.6 and multiple older AOS-8 branches). Organizations running Aruba infrastructure should prioritize upgrading to vendor-remediated releases per HPESBNW05026 and plan migration off EoM versions where patches are unavailable.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
HKCERT published a security bulletin warning about multiple vulnerabilities affecting Aruba products, reflecting broader public notification of the issues and encouraging review of remediation guidance.
HPE published security advisory AV26-196 and Security Bulletin HPESBNW05026 rev.1 addressing multiple vulnerabilities in Aruba Networking products, including ArubaOS AOS-8 and AOS-10 used by Mobility Conductors, Controllers, Gateways, and Access Points. The advisory directed customers to review affected versions and apply the necessary updates.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.