{"api_version":"v1","generated_at":"2026-10-10T09:10:00+00:00","product":{"cve_count":3,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-hewlett-packard-enterprise-hpe-hpe-aruba-networking-wireless-operating-systems-aos-8-and-aos-10-d2fde304378e","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"HPE Aruba Networking Wireless Operating Systems (AOS-8 & AOS-10)","next_cursor":null,"observations":[{"affected":"10.8.0.0; 10.7.0.0 \u2264 10.7.2.2; 10.4.0.0 \u2264 10.4.1.10; 8.13.0.0 \u2264 8.13.1.1; 8.12.0.0 \u2264 8.12.0.6; 8.10.0.0 \u2264 8.10.0.21","affected_versions_present":true,"cve_id":"CVE-2026-23812","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-23812","fixed":"Upgrade Mobility Conductors, Controllers, Gateways, and Access Points to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerabilities described in the details section: - AOS-10.8.x.x: 10.8.0.1 and above - AOS-10.7.x.x: 10.7.2.3 and above - AOS-10.4.x.x: 10.4.1.11 and above - AOS-8.13.x.x: 8.13.1.2 and above - AOS-8.12.x.x: 8.12.0.7 and above - AOS-8.10.x.x: 8.10.0.22 and above(*) (*) Fix for the CVE-2026-23812 specifically will be included in AOS-8.10.0.23. Please refer to the CVE-2026-23812 vulnerability description noted above for more details. Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/globalsearch#tab=Software HPE Aruba Networking does not evaluate or patch AOS-10 and AOS-8 software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw.","last_modified":"2026-04-01T16:21:09.805Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2026-03-04T16:13:48.086Z"},{"affected":"10.8.0.0; 10.7.0.0 \u2264 10.7.2.2; 10.4.0.0 \u2264 10.4.1.10; 8.13.0.0 \u2264 8.13.1.1; 8.12.0.0 \u2264 8.12.0.6; 8.10.0.0 \u2264 8.10.0.21","affected_versions_present":true,"cve_id":"CVE-2026-23811","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-23811","fixed":"Upgrade Mobility Conductors, Controllers, Gateways, and Access Points to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerabilities described in the details section: - AOS-10.8.x.x: 10.8.0.1 and above (Release ETA: First half of March 2026); - AOS-10.7.x.x: 10.7.2.3 and above; - AOS-10.4.x.x: 10.4.1.11 and above; - AOS-8.13.x.x: 8.13.1.2 and above; - AOS-8.12.x.x: 8.12.0.7 and above (Release ETA: Second half of March 2026); - AOS-8.10.x.x: 8.10.0.22 and above (Release ETA: First half of March 2026). Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/globalsearch#tab=Software HPE Aruba Networking does not evaluate or patch AOS-10 and AOS-8 software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw.","last_modified":"2026-04-01T16:21:29.217Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2026-03-04T16:12:32.715Z"},{"affected":"10.8.0.0; 10.7.0.0 \u2264 10.7.2.2; 10.4.0.0 \u2264 10.4.1.10; 8.13.0.0 \u2264 8.13.1.1; 8.12.0.0 \u2264 8.12.0.6; 8.10.0.0 \u2264 8.10.0.21","affected_versions_present":true,"cve_id":"CVE-2026-23810","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-23810","fixed":"Upgrade Mobility Conductors, Controllers, Gateways, and Access Points to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerabilities described in the details section: - AOS-10.8.x.x: 10.8.0.1 and above (Release ETA: First half of March 2026); - AOS-10.7.x.x: 10.7.2.3 and above; - AOS-10.4.x.x: 10.4.1.11 and above; - AOS-8.13.x.x: 8.13.1.2 and above; - AOS-8.12.x.x: 8.12.0.7 and above (Release ETA: Second half of March 2026); - AOS-8.10.x.x: 8.10.0.22 and above (Release ETA: First half of March 2026). Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/globalsearch#tab=Software HPE Aruba Networking does not evaluate or patch AOS-10 and AOS-8 software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw.","last_modified":"2026-04-01T16:21:49.641Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2026-03-04T16:11:35.964Z"}],"source_generated_at":"2026-10-10T06:21:41.304Z","vendor":"Hewlett Packard Enterprise (HPE)"}}
