CVE-2021-37726: Arubanetworks Aruba Instant

Critical severity, CVSS 9.8. EPSS: 2.4% chance of exploitation in the next 30 days.

A remote buffer overflow vulnerability was discovered in HPE Aruba Instant (IAP) version(s): Aruba Instant 8.7.x.x: 8.7.0.0 through 8.7.1.2. Aruba has released patches for Aruba Instant (IAP) that address this security vulnerability.

Affected products

  • Arubanetworks Aruba Instant: from 8.7.0.0, before 8.7.1.3 (fixed in 8.7.1.3)
  • Siemens Scalance w1750d Firmware: before 8.7.1.3 (fixed in 8.7.1.3)

Published 2021-10-12. Last modified 2026-06-17.