{"api_version":"v1","generated_at":"2026-10-10T10:05:00+00:00","product":{"cve_count":3,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-hewlett-packard-enterprise-hpe-hpe-aruba-networking-wireless-operating-system-aos-10-and-aos-8-b0e3434fc367","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"HPE Aruba Networking Wireless Operating System (AOS-10 & AOS-8)","next_cursor":null,"observations":[{"affected":"10.8.0.0; 10.7.0.0 \u2264 10.7.2.2; 10.4.0.0 \u2264 10.4.1.10; 8.13.0.0 \u2264 8.13.1.1; 8.12.0.0 \u2264 8.12.0.6; 8.10.0.0 \u2264 8.10.0.21","affected_versions_present":true,"cve_id":"CVE-2026-23809","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-23809","fixed":"Upgrade Mobility Conductors, Controllers, Gateways, and Access Points to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerabilities described in the details section: - AOS-10.8.x.x: 10.8.0.1 and above (Release ETA: First half of March 2026); - AOS-10.7.x.x: 10.7.2.3 and above; - AOS-10.4.x.x: 10.4.1.11 and above; - AOS-8.13.x.x: 8.13.1.2 and above; - AOS-8.12.x.x: 8.12.0.7 and above (Release ETA: Second half of March 2026); - AOS-8.10.x.x: 8.10.0.22 and above (Release ETA: First half of March 2026). Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/globalsearch#tab=Software HPE Aruba Networking does not evaluate or patch AOS-10 and AOS-8 software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw.","last_modified":"2026-04-01T16:22:10.710Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2026-03-04T16:10:02.829Z"},{"affected":"10.8.0.0; 10.7.0.0 \u2264 10.7.2.2; 10.4.0.0 \u2264 10.4.1.10; 8.13.0.0 \u2264 8.13.1.1; 8.12.0.0 \u2264 8.12.0.6; 8.10.0.0 \u2264 8.10.0.21","affected_versions_present":true,"cve_id":"CVE-2026-23808","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-23808","fixed":"Upgrade Mobility Conductors, Controllers, Gateways, and Access Points to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerabilities described in the details section: - AOS-10.8.x.x: 10.8.0.1 and above - AOS-10.7.x.x: 10.7.2.3 and above - AOS-10.4.x.x: 10.4.1.11 and above - AOS-8.13.x.x: 8.13.1.2 and above - AOS-8.12.x.x: 8.12.0.7 and above - AOS-8.10.x.x: 8.10.0.22 and above NOTE: After upgrading AOS software, the \"group-frame-block\" setting must also be enabled to fully mitigate the vulnerabilities. Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/globalsearch#tab=Software HPE Aruba Networking does not evaluate or patch AOS-10 and AOS-8 software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw.","last_modified":"2026-04-01T16:22:33.826Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2026-03-04T16:09:17.967Z"},{"affected":"10.8.0.0; 10.7.0.0 \u2264 10.7.2.2; 10.4.0.0 \u2264 10.4.1.10; 8.13.0.0 \u2264 8.13.1.1; 8.12.0.0 \u2264 8.12.0.6; 8.10.0.0 \u2264 8.10.0.21","affected_versions_present":true,"cve_id":"CVE-2026-23601","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-23601","fixed":"Upgrade Mobility Conductors, Controllers, Gateways, and Access Points to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerabilities described in the details section: - AOS-10.8.x.x: 10.8.0.1 and above - AOS-10.7.x.x: 10.7.2.3 and above - AOS-10.4.x.x: 10.4.1.11 and above - AOS-8.13.x.x: 8.13.1.2 and above - AOS-8.12.x.x: 8.12.0.7 and above - AOS-8.10.x.x: 8.10.0.22 and above NOTE: After upgrading AOS software, the \"group-frame-block\" setting must also be enabled to fully mitigate the vulnerabilities. Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/globalsearch#tab=Software HPE Aruba Networking does not evaluate or patch AOS-10 and AOS-8 software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw.","last_modified":"2026-04-01T16:23:06.986Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2026-03-04T16:07:42.929Z"}],"source_generated_at":"2026-10-10T06:21:41.304Z","vendor":"Hewlett Packard Enterprise (HPE)"}}
