CVE-2026-76747: Unauthenticated Buffer Overflow Vulnerabilities lead to Information Disclosure in AOS-S
Published Oct 6, 2026
·Updated
Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation could allow an unauthenticated remote attacker to expose sensitive memory contents and cause a denial of service on the device.
Affected Software
1 affected component
Aruba AOS-S
Event History
Oct 6, 2026
CVE Published
via MITRE·07:06 PM
Data Sourced
via MITRE·07:06 PM
DescriptionSeverity
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An unauthenticated remote attacker can exploit the affected AOS-S interface. No privileges or user interaction are required.
2
What impact should responders expect from successful exploitation?
Successful exploitation can disclose sensitive contents from device memory and cause a denial of service on the affected device. The available data does not indicate an integrity impact.
3
Is the vulnerable interface exposed by default?
The available information identifies an affected AOS-S interface but does not state whether it is enabled or network-accessible by default.