CVE-2026-44880: HPE Arubaos-Cx

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

A buffer overflow vulnerability was found in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow an remote low-privileged user to execute arbitrary code as a privileged user on the underlying operating system.

Affected products

  • HPE Arubaos-Cx: up to and including 10.13.1170; from 10.16.0000, up to and including 10.16.1050; from 10.17.0000, up to and including 10.17.1020; from 10.18.0000, up to and including 10.18.0001

Published 2026-07-21. Last modified 2026-08-11.