Summary
- October fixes cover ClearPass Policy Manager and AOS-Switch.
- Risks include RCE, SQL injection, privilege escalation and denial of service.
- Corrected releases are available for the affected software branches.
HPE Aruba Networking has released security fixes for vulnerabilities affecting ClearPass Policy Manager and AOS-Switch, including weaknesses capable of remote code execution, privilege escalation and bypassing security controls.
Two HPE security bulletins issued on 6 October cover the affected products, while France’s CERT-FR consolidated their risks on Wednesday. Other potential consequences include SQL injection, cross-site scripting, loss of data confidentiality or integrity and remote denial of service.
ClearPass occupies a sensitive position because it is used to make network access decisions based on identity, device information and organisational policy. Deployments can determine whether a user or endpoint is admitted to a network and which resources become available afterwards.
A weakness in that control layer can therefore affect more than the ClearPass management interface. Privilege escalation or security policy bypass can undermine assumptions made elsewhere in the network about which users and devices have already been authenticated or evaluated.
CERT-FR identifies ClearPass Policy Manager releases before 6.11.16 and before 6.14.1 as affected within their respective branches. AOS-Switch versions earlier than 16.11.0032 are also included.
The individual vulnerabilities have different prerequisites and effects rather than forming a single exploit chain. Some can allow arbitrary remote code execution, while others affect database queries, web interfaces, permissions or service availability.
ClearPass commonly integrates with directory services, authentication systems and network devices, giving administrative compromise potential consequences beyond the application itself. Information about those relationships, credentials or configuration can provide further value to an attacker who gains sufficient access.
AOS-Switch creates a separate operational challenge because switching infrastructure directly carries production network traffic. Software changes may require planned maintenance, redundancy checks and compatibility testing where organisations depend on stable switching environments.
Running both products also means remediation cannot be reduced to one update. Correcting a ClearPass deployment does not change an affected AOS-Switch, and operators need to match the software present in each part of the network to the appropriate fixed release.
HPE Aruba published other ClearPass security fixes earlier in 2026, so organisations that have fallen behind on updates may face exposure from more than the weaknesses documented this week. The October bulletins represent new disclosures rather than a repetition of the earlier set.
CERT-FR does not report active exploitation of the newly disclosed vulnerabilities. Their significance instead comes from the range of technical outcomes and the position of ClearPass and AOS-Switch inside enterprise identity and network infrastructure.
Updating affected software closes the documented vulnerabilities, while evidence suggesting an existing intrusion would require a separate investigation into credentials, configuration changes and activity occurring before remediation. The presence of a vulnerable version alone does not establish that compromise has taken place.





