VDB
CVE-2026-48020
CVE-2026-48020
PUBLISHED
On July 21, 2026, HPE published security advisories to address vulnerabilities in the following products. Include was a critical update for the following: HPE Aruba Networking Private 5G Core – versions 1.26.1.1 and prior HPE Aruba Networking EdgeConnect SD-WAN Gateways – multiple versions and platforms The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.
EPSS 0.77% · 53.4th percentile
Risk Scores
EPSS Score
0.77%
53.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| HPE | HPE Aruba Networking EdgeConnect SD-WAN Gateways – multiple versions and platforms | |
| HPE | HPE Aruba Networking Private 5G Core – versions 1.26.1.1 and prior |
Timeline
- Jun 5, 2026 CVE Published
- Jun 12, 2026 Security Advisory
- Aug 7, 2026 EPSS Score
- Aug 24, 2026 EPSS Score
- Aug 26, 2026 EPSS Score
- Aug 28, 2026 EPSS Score
- Aug 30, 2026 EPSS Score
- Sep 2, 2026 CVE Updated
- Sep 2, 2026 Distribution Patch
- Sep 3, 2026 EPSS Score
- Sep 5, 2026 EPSS Score
- Sep 6, 2026 EPSS Score
References
- https://cyber.gc.ca/en/alerts-advisories/hpe-security-advisory-av26-727 advisory
- https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05083en_us&docLocale=en_US#hpesbnw05083-rev-1-private-5g-core-traefik-strippr-0 vendor
- https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05013en_us&docLocale=en_US#hpesbnw05013-rev-1-hpe-aruba-networking-edgeconnec-0 vendor
- https://support.hpe.com/connect/s/securitybulletinlibrary?language=en_US vendor