CVE-2026-73780: HPE Arubaos-Cx
High severity, CVSS 8.3. EPSS: 0.2% chance of exploitation in the next 30 days.
A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Request Forgery (CSRF) protection. This could allow a remote unauthenticated attacker to execute arbitrary input against the affected interface if the attacker can convince an authenticated user of the interface to interact with a specially crafted URL.
Affected products
- HPE Arubaos-Cx: before 10.10.1181 (fixed in 10.10.1181); from 10.13.0000, before 10.13.1190 (fixed in 10.13.1190); from 10.16.0000, before 10.16.1060 (fixed in 10.16.1060); from 10.17.0000, before 10.17.1030 (fixed in 10.17.1030); version 10.18.0001 only
Published 2026-09-01. Last modified 2026-09-22.