CVE-2026-23815: HPE Arubaos-Cx
High severity, CVSS 7.2. EPSS: 1% chance of exploitation in the next 30 days.
A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute unauthorized commands.
Affected products
- HPE Arubaos-Cx: before 10.10.1180 (fixed in 10.10.1180); from 10.13.0000, before 10.13.1161 (fixed in 10.13.1161); from 10.16.0000, before 10.16.1030 (fixed in 10.16.1030); from 10.17.0000, before 10.17.1001 (fixed in 10.17.1001)
Published 2026-03-11. Last modified 2026-09-22.