CVE-2026-73752: HPE Arubaos-Cx
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. Successful exploitation of this vulnerability allows an attacker to write arbitrary files to the underlying operating system, which could lead to remote code execution.
Affected products
- HPE Arubaos-Cx: before 10.10.1181 (fixed in 10.10.1181); from 10.13.0000, before 10.13.1190 (fixed in 10.13.1190); from 10.16.0000, before 10.16.1060 (fixed in 10.16.1060); from 10.17.0000, before 10.17.1030 (fixed in 10.17.1030); version 10.18.0001 only
Published 2026-09-01. Last modified 2026-09-22.