CVE-2026-76745: Unauthenticated Adjacent Memory Corruption Vulnerabilities Leading to Remote Code Execution in AOS-S
Memory corruption vulnerabilities exist in AOS-S that are reachable by an unauthenticated adjacent attacker. Successful exploitation could allow an attacker to execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be on an adjacent network and does not need to authenticate or obtain user interaction. The impact is remote code execution with high confidentiality, integrity, and availability effects.
Is there evidence here that a default configuration is affected?
No. The available information identifies Aruba Networks AOS-S and an unauthenticated adjacent attack path, but does not state which configurations, releases, or default deployments are affected.
What can be done if patching cannot be performed immediately?
The provided information does not specify mitigations or workarounds. Because exploitation is possible from an adjacent network without authentication, restrict access from adjacent networks where operationally feasible until vendor guidance can be applied.