CVE-2026-23814: HPE Arubaos-Cx

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

A vulnerability in the command parameters of a certain AOS-CX CLI command could allow a low-privilege authenticated remote attacker to inject malicious commands resulting in unwanted behavior.

Affected products

  • HPE Arubaos-Cx: before 10.10.1180 (fixed in 10.10.1180); from 10.13.0000, before 10.13.1161 (fixed in 10.13.1161); from 10.16.0000, before 10.16.1030 (fixed in 10.16.1030); from 10.17.0000, before 10.17.1001 (fixed in 10.17.1001)

Published 2026-03-11. Last modified 2026-09-22.