HPE Aruba Networking AOS-CX Switches Vulnerabilities & Security Advisories
48 advisories tracked · HPE Aruba Networking Security Advisories (PSIRT) via NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published HPE Aruba Networking advisory that VulniPulse classified as AOS-CX Switches, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 2 critical, 28 high, 17 medium, 1 low.
Android app · Google Play
Monitor Aruba CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
HPE Aruba Networking Security Advisories (PSIRT) via NVD
Aruba's PSIRT bulletin portal (arubanetworks.com) is a JavaScript app with no stable public feed, so VulniPulse ingests Aruba's CVEs from NVD. Aruba publishes under the shared HPE CNA (security-alert@hpe.com), which also covers non-networking HPE products — so this feed is filtered to the full HPE Aruba Networking portfolio: ClearPass, AOS-8 mobility controllers, AOS-10 gateways and APs, Instant APs, AOS-CX and legacy AOS-Switch, Aruba Central, Fabric Composer and EdgeConnect/Silver Peak SD-WAN. Each entry links back to the official Aruba/HPE advisory when NVD carries the reference.
Latest Aruba AOS-CX Switches advisories
High [CVE-2026-73751] Authenticated Remote Command Injection in AOS-CX Web-based Management Interface
An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system. Affected product named by the advisory: AOS-CX.
High [CVE-2026-73750] Authenticated Buffer Overflow Vulnerabilities in AOS-CX API Endpoint Leads to Possible Code Execution
Vulnerabilities exist in the authentication module that may improperly process malformed or truncated input. An authenticated remote attacker could exploit these vulnerabilities by providing specially crafted input from a compromised or hostile authentication server. Successful exploitation could result in a Denial-of-Service or potential remote code execution with elevated privileges. Affected product named by the advisory: AOS-CX.
High [CVE-2026-63454] AOS-CX: authenticated path traversal vulnerability exists in AOS-CX
An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location from the command line interface of the underlying operating system, which could lead to remote code execution.
High [CVE-2026-63453] AOS-CX: Buffer overflow vulnerabilities exist in the command line interface of AOS-CX
Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow a remote high-privileged user to execute arbitrary code as a privileged user on the underlying operating system.
High [CVE-2026-44880] AOS-CX: buffer overflow vulnerability was found in the command line interface of AOS-CX
A buffer overflow vulnerability was found in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow an remote low-privileged user to execute arbitrary code as a privileged user on the underlying operating system.
High [CVE-2026-23816] vulnerability in the command line interface of AOS-CX Switches could
A vulnerability in the command line interface of AOS-CX Switches could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.
High [CVE-2026-23815] vulnerability in a custom binary used in AOS-CX Switches' CLI could
A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute unauthorized commands.
High [CVE-2026-23814] vulnerability in the command parameters of a certain AOS-CX CLI command could
A vulnerability in the command parameters of a certain AOS-CX CLI command could allow a low-privilege authenticated remote attacker to inject malicious commands resulting in unwanted behavior.