CVE-2026-23813: HPE Arubaos-Cx
Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.
A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable resetting the admin password.
Affected products
- HPE Arubaos-Cx: before 10.10.1180 (fixed in 10.10.1180); from 10.13.0000, before 10.13.1161 (fixed in 10.13.1161); from 10.16.0000, before 10.16.1030 (fixed in 10.16.1030); from 10.17.0000, before 10.17.1001 (fixed in 10.17.1001)
Published 2026-03-11. Last modified 2026-09-22.