CVE-2026-63454: HPE Arubaos-Cx

High severity, CVSS 7.2. EPSS: 0.9% chance of exploitation in the next 30 days.

An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location from the command line interface of the underlying operating system, which could lead to remote code execution.

Affected products

  • HPE Arubaos-Cx: up to and including 10.13.1170; from 10.16.0000, up to and including 10.16.1050; from 10.17.0000, up to and including 10.17.1020; from 10.18.0000, up to and including 10.18.0001

Published 2026-07-21. Last modified 2026-08-11.