CVE-2026-23817: HPE Arubaos-Cx

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability in the web-based management interface of AOS-CX Switches could allow an unauthenticated remote attacker to redirect users to an arbitrary URL.

Affected products

  • HPE Arubaos-Cx: from 10.06.0000, before 10.10.1180 (fixed in 10.10.1180); from 10.13.0000, before 10.13.1161 (fixed in 10.13.1161); from 10.16.0000, before 10.16.1030 (fixed in 10.16.1030); from 10.17.0000, before 10.17.1001 (fixed in 10.17.1001)

Published 2026-03-11. Last modified 2026-06-17.