CVE-2026-44872Disclosure(arubanetworks / arubaos)

LOWCVSS 7.2 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for arubanetworks arubaos systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A command injection vulnerability exists in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to place arbitrary files on the underlying filesystem of the affected device.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • arubaos
  • sd-wan

Threat summary

  • Active exploitation appears in 1 classified signals
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-12); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
arubaossd-wan

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-12: 2Mentions · 2026-05-18: 1Active Exploitation · 2026-05-18: 1Technical Details · 2026-05-12: 205-1205-18
Signal classification2 categories
Disclosure
266.7%
Active Exploitation
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-122
Disclosure2
2026-05-181
Active Exploitation1
Full discourse3 posts
  • VulDB 🛡@vuldb
    Active Exploitation

    Our CTI team identified a lot of activities targeting HPE Aruba Networking Wireless Operating System (CVE-2026-44872) https://vuldb.com/vuln/363345/cti

    Post summary

    The post indicates widespread exploitation activity for CVE‑2026‑44872, but provides no technical details or mitigation information.

    0000071
    2.2K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-44872 A command injection vulnerability exists in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authentic… https://www.cve.org/CVERecord?id=CVE-2026-44872 ----- Traducción: CVE-2026-44872 Exi… http://infoflow.cloud`

    Post summary

    The text announces a new command injection vulnerability (CVE-2026-44872) in AOS-8/AOS-10 systems and provides basic technical details but lacks specific PoC, exploit tools, or patch information.

    0000031
    77 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-44872 A command injection vulnerability exists in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authentic… https://www.cve.org/CVERecord?id=CVE-2026-44872

    Post summary

    The text announces a command injection vulnerability (CVE-2026-44872) in AOS-8 and AOS-10 but provides no proof of concept, exploitation evidence, or remediation information.

    00000124
    57.5K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSarubanetworksarubaos---
Apparubanetworkssd-wan---

Explore more