HPE security advisory (AV26-909)
Canada's Cyber Centre relayed HPE advisories covering vulnerabilities in Aruba ClearPass Policy Manager and HPE IceWall products.
Canadian Centre for Cyber Security advisory AV26-909, dated September 10, 2026, flags vulnerabilities in HPE products disclosed on September 9, 2026. Affected products include Aruba ClearPass Policy Manager versions prior to or equal to 6.11.14 and 6.12.8, and multiple HPE IceWall versions and models. Bulletins cover multiple ClearPass vulnerabilities, a remote bypass of security restrictions in IceWall, and an IceWall denial-of-service vulnerability; administrators are urged to review the bulletins and apply updates.
- IceWall flaws include remote bypass of security restrictions and a denial-of-service vulnerability
- No CVE identifiers are listed in the Canadian advisory text
Full article107 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-909
Date: September 10, 2026
As of September 9, 2026, Hewlett Packard Enterprise (HPE) is affected by vulnerabilities in the following products:
- ClearPass Policy Manager (CPPM)
- Prior to or equal to 6.11.14
- Prior to or equal to 6.12.8
- HPE IceWall products
- Multiple versions and models
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/hpe-security-advisory-av26-909