Skip to content
TrustList
News

HPE fixes 37 flaws in AOS-Switch and ClearPass Policy Manager

Editorial

By TrustList Editorial

Sixteen are rated critical and 12 high. Italy's national cyber agency lists remote code execution and authentication bypass among the flaw types and records no public exploit or exploitation.

About HPE fixes 37 flaws in AOS-Switch and ClearPass Policy Manager

HPE fixes 37 flaws in AOS-Switch and ClearPass Policy Manager

7 October 2026: HPE has released security updates for AOS-Switch (AOS-S) and ClearPass Policy Manager (CPPM) that together close 37 vulnerabilities, 16 of them rated critical and 12 high, according to an alert from Italy's national cybersecurity agency, ACN. The agency lists remote code execution and authentication bypass among the flaw types, and its CVE table shows no public proof of concept and no known exploitation at publication on 7 October.

Not yet independently verified. We could read only the Italian ACN alert. HPE's bulletin pages (hpesbnw05158en_us and hpesbnw05156en_us) did not load for us, so fixed version numbers and per-flaw CVSS scores are not given here. We will update this when it can be confirmed, and remove this note.

ACN's alert, number AL09/261007/CSIRT-ITA, names the vulnerable releases:

  • AOS-S: version 16.11.0031 and earlier
  • ClearPass Policy Manager: 6.14.0 and earlier, and 6.11.15 and earlier

The two lines for ClearPass mean customers on either the 6.14 or the 6.11 branch are covered. The alert lists 28 CVE identifiers, the critical and high ones only, starting with CVE-2026-79811 and running down through CVE-2026-79794, plus a second range from CVE-2026-76754 to CVE-2026-76742. It describes the full set of weakness types as remote code execution, authentication bypass, privilege escalation, arbitrary file read, tampering, security restriction bypass, information disclosure and denial of service.

The agency says HPE's own security bulletins carry the fixes, and points to two of them, hpesbnw05158en_us and hpesbnw05156en_us, for the patched releases. Its mitigation advice is to follow those bulletins and update.

The two products sit in different places. AOS-S runs on access switches, while ClearPass is the policy and network access control server that decides which users and devices are admitted. A flaw in an authentication product deserves attention first, because it governs access to everything behind it. Teams that run both can check the installed release against the lists above before reading the bulletins for the fixed builds.

Sources

Categories & features

TrustList Weekly

The week in software and IT, in one email

The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.

We will email you to confirm. Unsubscribe with one click in any issue. Privacy policy