Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · arubanetworks

arubanetworks

· 70 Critical

Total CVEs

584

Critical

70

Products

214

Search All CVEs →

584

Products (214)

arubaos227 CVEsclearpass policy manager136 CVEssd-wan97 CVEsclearpass36 CVEsairwave36 CVEs703033 CVEs728033 CVEs701033 CVEs7240xm33 CVEs722033 CVEs721033 CVEs720533 CVEsinstant33 CVEsedgeconnect sd-wan orchestrator29 CVEs9004-lte26 CVEs901226 CVEs900426 CVEsedgeconnect enterprise25 CVEsmc-va-1k22 CVEsmcr-va-5k22 CVEsmcr-va-50022 CVEsmcr-va-5022 CVEsmcr-va-1k22 CVEsmcr-va-10k22 CVEsmcr-hw-5k22 CVEsmcr-hw-1k22 CVEsmcr-hw-10k22 CVEsmc-va-5022 CVEsmc-va-1022 CVEsmc-va-25022 CVEscx 832017 CVEscx 832517 CVEsaruba edgeconnect enterprise orchestrator16 CVEscx 6200f16 CVEscx 640016 CVEscx 840016 CVEscx 630016 CVEscx 836014 CVEs700514 CVEs700814 CVEs702414 CVEsaos-cx12 CVEsairwave glass12 CVEsaruba instant12 CVEscx 1000012 CVEscx 930012 CVEscx 600011 CVEscx 610011 CVEscx 4100i11 CVEs92409 CVEsap-6357 CVEsap-6557 CVEsap-6346 CVEs91066 CVEs91146 CVEsap-6546 CVEsvx-80005 CVEs2540 firmware5 CVEs25405 CVEs29205 CVEs2920 firmware5 CVEsnx-7005 CVEsvx-10005 CVEsvx-20005 CVEsvx-30005 CVEsvx-5005 CVEsvx-50005 CVEsvx-60005 CVEsvx-70005 CVEsvx-90005 CVEsfabric composer5 CVEs25304 CVEsaruba 5412r zl24 CVEs2530 firmware4 CVEsaruba mobility controller4 CVEsaruba 2530ya4 CVEsaruba 25404 CVEsaruba 2930m4 CVEsaruba 2530yb4 CVEsaruba 2930f4 CVEsaruba 29204 CVEsaruba 3810m4 CVEsaruba 5406r zl24 CVEs3810 firmware3 CVEs2930 firmware3 CVEsnx-80003 CVEs29303 CVEsnx-90003 CVEsnx-30003 CVEs5400r firmware3 CVEsnx-11k3 CVEsaos-cx firmware3 CVEsnx-10k3 CVEsnx-20003 CVEsaruba 25303 CVEsnx-10003 CVEsnx-60003 CVEs5400r3 CVEsnx-50003 CVEsnx-70003 CVEs38103 CVEs5412r2 CVEscx 6300 firmware2 CVEscx 6400 firmware2 CVEscx 8320 firmware2 CVEscx 8325 firmware2 CVEscx 8400 firmware2 CVEs26152 CVEs2615 firmware2 CVEs26202 CVEs2620 firmware2 CVEs29152 CVEs2915 firmware2 CVEs2930f2 CVEs2930f firmware2 CVEs2930m2 CVEs2930m firmware2 CVEs3810m2 CVEs3810m firmware2 CVEsnx-107002 CVEsnx-117002 CVEsnx-17002 CVEsnx-27002 CVEsnx-37002 CVEsnx-57002 CVEsnx-67002 CVEsnx-77002 CVEsnx-87002 CVEsnx-97002 CVEs5406r2 CVEs5406r firmware2 CVEscx 6200f firmware2 CVEs5412r firmware2 CVEsweb management portal1 CVEs203r firmware1 CVEs203rp1 CVEs203rp firmware1 CVEs2530 10\/100 port1 CVEs2530 10\/100 port firmware1 CVEs2530 with gigt port1 CVEs2530 with gigt port firmware1 CVEsanalytics and location engine1 CVEsap-1031 CVEsap-1141 CVEsap-1151 CVEsap-1201 CVEsap-1211 CVEsap-1301 CVEsap-1351 CVEsap-2041 CVEsap-2051 CVEsap-2071 CVEsap-2141 CVEsap-2151 CVEsap-2241 CVEsap-2251 CVEsap-300 series access points1 CVEsap-300 series access points firmware1 CVEsap-300 series instant access points1 CVEsap-300 series instant access points firmware1 CVEsap-3031 CVEsap-3041 CVEsap-3051 CVEsap-3141 CVEsap-3151 CVEsap-3181 CVEsap-3241 CVEsap-3251 CVEsap-3341 CVEsap-3401 CVEsap-3701 CVEsap-5041 CVEsap-5051 CVEsap-5141 CVEsap-5151 CVEsap-5341 CVEsap-5351 CVEsap-5551 CVEsaruba 2530ya firmware1 CVEsaruba 2530yb firmware1 CVEsaruba 2540 firmware1 CVEsaruba 26201 CVEsaruba 2620 firmware1 CVEsaruba 2920 firmware1 CVEsaruba 2930f firmware1 CVEsaruba 2930m firmware1 CVEsaruba 38001 CVEsaruba 3800 firmware1 CVEsaruba 3810m firmware1 CVEsaruba 5406r zl2 firmware1 CVEsaruba 5412r zl2 firmware1 CVEsaruba mobility controller1 CVEsclearpass guest1 CVEsiap-1031 CVEsiap-1141 CVEsiap-1151 CVEsiap-2041 CVEsiap-2051 CVEsiap-2071 CVEsiap-2241 CVEsiap-2251 CVEsiap-3041 CVEsiap-3051 CVEsiap-3141 CVEsiap-3151 CVEsiap-3181 CVEsiap-3241 CVEsiap-3251 CVEsiap-3341 CVEsinstant access point1 CVEsinstant access point firmware1 CVEsrap-1081 CVEsrap-1091 CVEs203r1 CVEs

Recent Vulnerabilities

View all 584
CVE-2026-44871HIGH 7.2

Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.

CVE-2026-44874MEDIUM 4.9

A vulnerability exists in the web-based management interface of an AOS-10 Gateway that could allow an authenticated remote attacker to access sensitive files on the underlying operating system. Successful exploitation of this vulnerability could result in the disclosure of confidential system information, potentially enabling further attacks against the affected device.

CVE-2026-44873MEDIUM 5.4

A session management vulnerability in AOS-8 allows previously authenticated users to retain network access after their accounts are administratively disabled. Existing sessions are not invalidated when credentials are revoked, enabling continued access until session expiration. An attacker with compromised credentials could exploit this behavior to maintain unauthorized access even after the account has been disabled.

CVE-2026-44872HIGH 7.2

A command injection vulnerability exists in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to place arbitrary files on the underlying filesystem of the affected device.

CVE-2026-44870HIGH 7.2

Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.

CVE-2026-44869HIGH 7.2

Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.

CVE-2026-44868HIGH 7.2

Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.

CVE-2026-44867HIGH 7.2

Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.

CVE-2026-44866HIGH 7.2

Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.

CVE-2026-44865HIGH 7.2

Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.

CVE-2026-44864HIGH 7.2

SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative privileges could exploit these vulnerabilities by injecting crafted input into parameters that are passed unsanitized to backend database queries. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system.

CVE-2026-44863HIGH 7.2

SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative privileges could exploit these vulnerabilities by injecting crafted input into parameters that are passed unsanitized to backend database queries. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system.

CVE-2026-44862HIGH 7.2

SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative privileges could exploit these vulnerabilities by injecting crafted input into parameters that are passed unsanitized to backend database queries. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system.

CVE-2026-44861HIGH 7.2

SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative privileges could exploit these vulnerabilities by injecting crafted input into parameters that are passed unsanitized to backend database queries. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system.

CVE-2026-44860HIGH 7.2

SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative privileges could exploit these vulnerabilities by injecting crafted input into parameters that are passed unsanitized to backend database queries. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system.

CVE-2026-44859HIGH 7.2

Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authenticated attacker with administrative privileges could exploit these vulnerabilities by sending specially crafted requests to the affected services. Successful exploitation could allow the attacker to execute arbitrary code with elevated privileges on the underlying operating system.

CVE-2026-44858HIGH 7.2

Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authenticated attacker with administrative privileges could exploit these vulnerabilities by sending specially crafted requests to the affected services. Successful exploitation could allow the attacker to execute arbitrary code with elevated privileges on the underlying operating system.

CVE-2026-44857HIGH 7.2

Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authenticated attacker with administrative privileges could exploit these vulnerabilities by sending specially crafted requests to the affected services. Successful exploitation could allow the attacker to execute arbitrary code with elevated privileges on the underlying operating system.

CVE-2026-44856HIGH 7.2

Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authenticated attacker with administrative privileges could exploit these vulnerabilities by sending specially crafted requests to the affected services. Successful exploitation could allow the attacker to execute arbitrary code with elevated privileges on the underlying operating system.

CVE-2026-44855HIGH 7.2

Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authenticated attacker with administrative privileges could exploit these vulnerabilities by sending specially crafted requests to the affected services. Successful exploitation could allow the attacker to execute arbitrary code with elevated privileges on the underlying operating system.

CVE-2026-44854HIGH 7.2

Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to upload arbitrary files to the underlying operating system, potentially leading to remote code execution as a privileged user.

CVE-2026-44853HIGH 7.2

Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to upload arbitrary files to the underlying operating system, potentially leading to remote code execution as a privileged user.

CVE-2026-44852HIGH 7.2

An authenticated remote code execution vulnerability exists in the AOS-8 and AOS-10 web-based management interface. A vulnerability in the certificate download functionality could allow an authenticated remote attacker to overwrite arbitrary files on the underlying operating system by exploiting improper input validation in the file path parameter. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system as a privileged user.

CVE-2026-23827HIGH 7.5

A heap-based buffer overflow vulnerability exists in a Network management service of AOS-8 and AOS-10 that could allow an unauthenticated remote attacker to achieve remote code execution. Successful exploitation could allow an unauthenticated attacker to execute arbitrary code as a privileged user on the underlying operating system, potentially leading to a system compromise. Exploitation may also result in a denial-of-service (DoS) condition affecting the impacted system process.

CVE-2026-23826HIGH 7.5

A vulnerability in a network management service of AOS-8 Operating System could allow an unauthenticated remote attacker to exploit this vulnerability by sending specially crafted network packets to the affected device, potentially resulting in a denial-of-service condition. Successful exploitation could cause the affected service process to terminate unexpectedly, disrupting normal device operations.