CVE-2026-73764: HPE Arubaos-Cx

High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable unauthorized modification of affected resources and limited disruption of affected services.

Affected products

  • HPE Arubaos-Cx: up to and including 10.10.1180; from 10.13.0000, up to and including 10.13.1180; from 10.16.0000, up to and including 10.16.1051; from 10.17.0000, up to and including 10.17.1021; version 10.18.0001 only

Published 2026-09-01. Last modified 2026-09-04.