Skip to content
VulniPulse

HPE Aruba Networking AOS-CX Switches Vulnerabilities & Security Advisories

48 advisories tracked · HPE Aruba Networking Security Advisories (PSIRT) via NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published HPE Aruba Networking advisory that VulniPulse classified as AOS-CX Switches, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 2 critical, 28 high, 17 medium, 1 low.

Android app · Google Play

Monitor Aruba CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

HPE Aruba Networking Security Advisories (PSIRT) via NVD

Aruba's PSIRT bulletin portal (arubanetworks.com) is a JavaScript app with no stable public feed, so VulniPulse ingests Aruba's CVEs from NVD. Aruba publishes under the shared HPE CNA (security-alert@hpe.com), which also covers non-networking HPE products — so this feed is filtered to the full HPE Aruba Networking portfolio: ClearPass, AOS-8 mobility controllers, AOS-10 gateways and APs, Instant APs, AOS-CX and legacy AOS-Switch, Aruba Central, Fabric Composer and EdgeConnect/Silver Peak SD-WAN. Each entry links back to the official Aruba/HPE advisory when NVD carries the reference.

Latest Aruba AOS-CX Switches advisories

High8.8Aruba

High [CVE-2026-73752] AOS-CX: unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX

An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. Successful exploitation of this vulnerability allows an attacker to write arbitrary files to the underlying operating system, which could lead to remote code execution.

CVE-2026-73752
AOS-CXSwitches (AOS-CX)
Sep 1, 2026
High8.8Aruba

High [CVE-2026-73751] Authenticated Remote Command Injection in AOS-CX Web-based Management Interface

An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system. Affected product named by the advisory: AOS-CX.

CVE-2026-73751
AOS-CXSwitches (AOS-CX)
Sep 1, 2026
High8.8Aruba

High [CVE-2026-73750] Authenticated Buffer Overflow Vulnerabilities in AOS-CX API Endpoint Leads to Possible Code Execution

Vulnerabilities exist in the authentication module that may improperly process malformed or truncated input. An authenticated remote attacker could exploit these vulnerabilities by providing specially crafted input from a compromised or hostile authentication server. Successful exploitation could result in a Denial-of-Service or potential remote code execution with elevated privileges. Affected product named by the advisory: AOS-CX.

CVE-2026-73750
AOS-CXSwitches (AOS-CX)
Sep 1, 2026
Medium4.9Aruba

Medium [CVE-2026-73783] AOS-CX: Stack overflow vulnerabilities exist in an API endpoint of AOS-CX

Stack overflow vulnerabilities exist in an API endpoint of AOS-CX. Successful exploitation could allow an authenticated malicious actor to cause a denial-of-service condition on the affected system.

CVE-2026-73783
AOS-CXSwitches (AOS-CX)
Sep 1, 2026
Medium6.5Aruba

Medium [CVE-2026-73772] AOS-CX: Buffer overflow vulnerabilities exist in an underlying service of AOS-CX that could lead to an unauthenticated denial-of-service condition by sending specially crafted packets to the affected device

Buffer overflow vulnerabilities exist in an underlying service of AOS-CX that could lead to an unauthenticated denial-of-service condition by sending specially crafted packets to the affected device. Successful exploitation of these vulnerabilities results in a disruption of normal operation of the underlying operating system.

CVE-2026-73772
AOS-CXSwitches (AOS-CX)
Sep 1, 2026
Medium6.6Aruba

Medium [CVE-2026-73762] AOS-CX: vulnerability has been identified in the API endpoint of AOS-CX that could allow a remote actor to circumvent existing access controls

A vulnerability has been identified in the API endpoint of AOS-CX that could allow a remote actor to circumvent existing access controls. In some cases this could enable unauthorized access to management functionality that should be restricted by the configured access control policy.

CVE-2026-73762
AOS-CXSwitches (AOS-CX)
Sep 1, 2026
Medium6.5Aruba

Medium [CVE-2026-73761] AOS-CX: out-of-bounds read vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated information disclosure by sending a specially crafted packet

An out-of-bounds read vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated information disclosure by sending a specially crafted packet. Successful exploitation of this vulnerability results in the ability to disclose sensitive information from the underlying operating system.

CVE-2026-73761
AOS-CXSwitches (AOS-CX)
Sep 1, 2026
Medium6.5Aruba

Medium [CVE-2026-73760] AOS-CX: authenticated Path Traversal vulnerability exists in AOS-CX

An authenticated Path Traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to read arbitrary files from the web-based management interface of the underlying operating system, which could lead to remote unauthorized access to files.

CVE-2026-73760
AOS-CXSwitches (AOS-CX)
Sep 1, 2026
Medium6.5Aruba

Medium [CVE-2026-73759] AOS-CX: Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-of-service condition by sending specially crafted packets

Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-of-service condition by sending specially crafted packets. Successful exploitation of these vulnerabilities results in disruption of normal operation on affected devices.

CVE-2026-73759
AOS-CXSwitches (AOS-CX)
Sep 1, 2026
Medium6.5Aruba

Medium [CVE-2026-73758] AOS-CX: privilege escalation vulnerability exists in the API endpoint of AOS-CX

A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulnerable system.

CVE-2026-73758
AOS-CXSwitches (AOS-CX)
Sep 1, 2026
Medium6.4Aruba

Medium [CVE-2026-73757] AOS-CX: vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a server-side request forgery (SSRF) attack

A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a server-side request forgery (SSRF) attack. A successful exploit allows an attacker to enumerate information about the internal structure of the AOS-CX host, leading to potential disclosure and limited modification of sensitive information.

CVE-2026-73757
AOS-CXSwitches (AOS-CX)
Sep 1, 2026
Medium5.9Aruba

Medium [CVE-2026-73756] AOS-CX: vulnerability in an API endpoint of AOS-CX could allow a remote unauthenticated attacker to obtain sensitive information via a man-in-the-middle attack

A vulnerability in an API endpoint of AOS-CX could allow a remote unauthenticated attacker to obtain sensitive information via a man-in-the-middle attack. Successful exploitation allows an attacker to retrieve data which could be used to further compromise the confidentiality of the affected system.

CVE-2026-73756
AOS-CXSwitches (AOS-CX)
Sep 1, 2026
Medium5.7Aruba

Medium [CVE-2026-73755] AOS-CX: privilege escalation vulnerability exists in the API endpoint of AOS-CX

A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low-privilege operator user, after a required user action, to access sensitive information from the vulnerable system.

CVE-2026-73755
AOS-CXSwitches (AOS-CX)
Sep 1, 2026
Medium5.3Aruba

Medium [CVE-2026-73754] AOS-CX: Denial-of-service vulnerabilities exist in the command line interface of AOS-CX

Denial-of-service vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation could allow an authenticated user to disrupt the normal operation of a vulnerable system.

CVE-2026-73754
AOS-CXSwitches (AOS-CX)
Sep 1, 2026
High7.2Aruba Updated

High [CVE-2026-63454] AOS-CX: authenticated path traversal vulnerability exists in AOS-CX

An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location from the command line interface of the underlying operating system, which could lead to remote code execution.

CVE-2026-63454
AOS-CXSwitches (AOS-CX)
Jul 21, 2026
High7.2Aruba Updated

High [CVE-2026-63453] AOS-CX: Buffer overflow vulnerabilities exist in the command line interface of AOS-CX

Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow a remote high-privileged user to execute arbitrary code as a privileged user on the underlying operating system.

CVE-2026-63453
AOS-CXSwitches (AOS-CX)
Jul 21, 2026
High8.8Aruba Updated

High [CVE-2026-44880] AOS-CX: buffer overflow vulnerability was found in the command line interface of AOS-CX

A buffer overflow vulnerability was found in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow an remote low-privileged user to execute arbitrary code as a privileged user on the underlying operating system.

CVE-2026-44880
AOS-CXSwitches (AOS-CX)
Jul 21, 2026
Critical9.8Aruba

Critical [CVE-2026-23813] vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially

A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable resetting the admin password.

CVE-2026-23813
AOS-CXSwitches (AOS-CX)
Mar 11, 2026
High7.2Aruba

High [CVE-2026-23816] vulnerability in the command line interface of AOS-CX Switches could

A vulnerability in the command line interface of AOS-CX Switches could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.

CVE-2026-23816
AOS-CXSwitches (AOS-CX)
Mar 11, 2026
High7.2Aruba

High [CVE-2026-23815] vulnerability in a custom binary used in AOS-CX Switches' CLI could

A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute unauthorized commands.

CVE-2026-23815
AOS-CXSwitches (AOS-CX)
Mar 11, 2026

← All Aruba advisories