HPE security advisory (AV26-873)
Canada's Cyber Centre relays HPE advisories covering multiple vulnerabilities in Aruba AOS-CX switches and Fabric Composer, urging updates.
The Canadian Centre for Cyber Security issued advisory AV26-873 noting multiple vulnerabilities in HPE Aruba Networking AOS-CX and Fabric Composer. Affected versions span AOS-CX releases through branches 10.10, 10.13, 10.16, 10.17, and 10.18, and Fabric Composer through 7.3.3. Administrators are urged to review HPE bulletins HPESBNW05133 and HPESBNW05134 and apply available updates.
- Affects ArubaOS-CX branches up to 10.18.0001 and Fabric Composer up to 7.3.3.
- References HPE bulletins HPESBNW05133 and HPESBNW05134 for remediation details.
Full article115 words · extracted from cyber.gc.ca · click to collapse

Serial number: AV26-873
Date: September 2, 2026
As of September 1, 2026, Hewlett Packard Enterprise (HPE) is affected by vulnerabilities in the following products:
HPE Networking AOS-CX
Prior to or equal to 10.10.1180
Prior to or equal to 10.13.1180
Prior to or equal to 10.16.1051
Prior to or equal to 10.17.1021
Prior to or equal to 10.18.0001
HPE Networking Fabric Composer
Prior to or equal to 7.3.3
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
HPESBNW05133 rev.1 - Multiple Vulnerabilities in HPE Aruba Networking Fabric Composer
HPESBNW05134 rev.1 - Multiple Vulnerabilities in HPE Aruba Networking ArubaOS-CX (AOS-CX)
HPE Security Bulletin Library
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/hpe-security-advisory-av26-873