#ArubaOS
Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution.
HPE patches critical ArubaOS-CX remote code execution flaw
Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution.
www.bleepingcomputer.com
September 3, 2026 at 6:28 PM
Pre-auth XXE → HTTP SSRF on ArubaOS 8.13.2 closed as "theoretical / no valid PoC" despite TCP pcap, sshd localhost log, and internal port scan — documenting for community review
Pre-Authentication XXE → OOB SSRF in ArubaOS 8.13.2.0 (Port 32000)
A pre-authentication XXE injection on ArubaOS 8.13.2.0 port 32000 enables OOB SSRF. Confirmed via wire-level pcap and the controller's own sshd logs. Submitted to HPE Bugcrowd — closed as theoretical despite four evidence items.
netacoding.com
June 10, 2026 at 6:58 PM
📰 HPE Menambal Celah Kritis ArubaOS-CX yang Bisa Picu Remote Code Execution

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/09/04/hpe-patch-celah-kritis-arubaos-cx-rce/

#aruba #cybersecurity #hpe #keamananSiber #rce #teknologi #vulnerability
September 4, 2026 at 4:09 AM
Aufgrund von mehreren Sicherheitslücken in ArubaOS und InstantOS sind Schadcode-Attacken auf Aruba-Geräte möglich. #Security
Access Points von Aruba verwundbar – keine Updates für ältere Versionen
Aufgrund von mehreren Sicherheitslücken in ArubaOS und InstantOS sind Schadcode-Attacken auf Aruba-Geräte möglich.
www.heise.de
May 16, 2024 at 8:49 AM
Multiple Vulnerabilities in HPE Aruba Networking ArubaOS-CX (AOS-CX)
URL: support.hpe.com/hpesc/public...
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8
support.hpe.com
September 4, 2026 at 7:05 AM
A critical remote code execution flaw (CVE-2026-73749) in HPE ArubaOS-CX allows attackers to execute arbitrary code on affected devices #HPE #ArubaOSCX #CVE202673749 #RemoteCodeExecution http://portal.auscert.org.au/bulletins/ASB-2026.0209/
AUSCERT Portal - ASB-2026.0209
portal.auscert.org.au
September 4, 2026 at 1:41 PM
HPE Aruba hat eine Sicherheitsmitteilung zu mehreren Lücken herausgegeben. Angreifer können Befehle einschleusen oder einen DoS auslösen.
ArubaOS: Sicherheitslücken erlauben Befehlsschmuggel
HPE Aruba hat eine Sicherheitsmitteilung zu mehreren Lücken herausgegeben. Angreifer können Befehle einschleusen oder einen DoS auslösen.
www.heise.de
March 11, 2024 at 8:14 AM
HPE Patches Multiple ArubaOS-CX Vulnerabilities #ArubaOSCXxaVulnerabilitiesandExploits #CyberAdvisory #HPESecurity
HPE Patches Multiple ArubaOS-CX Vulnerabilities
 Hewlett Packard Enterprise has released a security advisory for Aruba Networking ArubaOS-CX, warning customers about multiple vulnerabilities affecting the switch operating system. The advisory, published on September 1, 2026, says HPE has issued updates to address the issues and urges administrators to review their deployments promptly.  According to the advisory and related vulnerability listings, the flaws span several categories. Some issues can expose sensitive information through API endpoints, while others may allow denial of service, stored cross-site scripting, arbitrary file write behavior, or path traversal under certain conditions. The breadth of the report suggests that both the management interface and backend API paths were part of the security review.  The most serious concerns are likely to be those that could let an authenticated attacker influence device behavior or reach deeper system components. One vulnerability involves an API endpoint that could allow a low-privilege authenticated operator to change certain settings, while another points to stored XSS in the web-based management interface. Other disclosures describe file-writing and traversal weaknesses that may, in some cases, lead to remote code execution or broader system compromise.  For enterprise users, the practical takeaway is simple: check which ArubaOS-CX version is deployed and compare it with the affected branches listed in public vulnerability records. Network administrators should prioritize patching, especially on systems used for core switching, segmentation, and centralized management. HPE’s release indicates that updates are available, making this a straightforward remediation case rather than a purely advisory-only notice.  Organizations using ArubaOS-CX should treat the bulletin as a reminder to keep network infrastructure current. Security gaps in switching platforms can have wider consequences than a single device issue, especially when they involve administrative interfaces and API access. Applying the vendor update and validating exposure across affected versions are the most important next steps.
dlvr.it
September 7, 2026 at 3:23 PM
HPE、ArubaOS-CXの重大なRCE脆弱性をパッチ

Hewlett Packard Enterprise (HPE)がArubaOS-CXネットワークOSの重大な脆弱性をパッチリリース。この脆弱性はリモートコード実行(RCE)を引き起こす可能性がある。ネットワークスイッチやルータの管理者は緊急のアップデート適用が推奨される。

#脆弱性 #情報セキュリティ
HPE、ArubaOS-CXの重大なRCE脆弱性をパッチ
Hewlett Packard Enterprise (HPE)がArubaOS-CXネットワークOSの重大な脆弱性をパッチリリース。この脆弱性はリモートコード実行(RCE)を引き起こす可能性がある。ネットワークスイッチやルータの管理者は緊急のアップデート適用が推奨される。
www.bleepingcomputer.com
September 6, 2026 at 1:01 PM
Sicherheitspatches fuer Switches mit ArubaOS-CX, sonst uebernehmen Angreifer die Kisten. Nach den Cisco-Switches diese Woche zeichnet sich ein Muster ab: Enterprise-Preise vorne, Bastelbuden-Codequalitaet hinten. Wer im Netzkern sitzt, sitzt ueberall.
Attacken auf Switches mit ArubaOS-CX moeglich
www.heise.de
September 6, 2026 at 7:08 AM
HPE Patches Critical RCE in ArubaOS-CX: Two Independent Exploit Paths in the Same Switch
HPE Patches Critical RCE in ArubaOS-CX: Two Independent Exploit Paths in the Same Switch
HPE released patches for 34 CVEs in ArubaOS-CX. Two independent unauthenticated RCE vulnerabilities in the same bulletin point to a systemic secure-development issue in the network OS.
deafnews.it
September 5, 2026 at 6:17 PM
Vierunddreissig Sicherheitsluecken in ArubaOS-CX auf einen Schlag gepatcht. In der Firmware der Switches, die euer Netz zusammenhalten. Das ist kein Patchday mehr, das ist eine Amnestie.
Sicherheitspatches fuer Switches mit ArubaOS-CX
www.heise.de
September 5, 2026 at 7:07 AM
Google patched Chrome's 6th zero-day of 2026 after active exploitation, alongside issues in SonicWall SMA1000, HPE ArubaOS-CX, and Cisco Nexus 9000. WordPress plugins and major breach disclosures also surfaced. #Chrome #SonicWall #France
Page Not Found - Cybersecurity News Everyday
www.hendryadrian.com
September 5, 2026 at 9:45 PM
HPE patched 34 ArubaOS-CX CVEs, including critical unauthenticated remote code execution flaws, and recommends restricting management interfaces to VLANs and firewalled layer 3 access.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 5, 2026 at 1:02 PM
HPE patches ArubaOS-CX switches vulnerable to remote code execution

www.scworld.com/news/hpe-pat...

#Kyberturvallisuus #Kyber #Tilannekuva
HPE patches ArubaOS-CX switches vulnerable to remote code execution
HPE patched 35 ArubaOS-CX flaws, including a critical bug that could enable remote code execution.
www.scworld.com
September 4, 2026 at 7:00 PM
HPE patches critical ArubaOS-CX remote code execution flaw

Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution. [...]
#hackernews #news
HPE patches critical ArubaOS-CX remote code execution flaw
Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution. [...]
www.bleepingcomputer.com
September 4, 2026 at 3:15 PM
Sicherheitspatches: Attacken auf Switches mit ArubaOS-CX möglich | Security www.heise.de/news/Sicherh...
Sicherheitspatches: Attacken auf Switches mit ArubaOS-CX möglich
Die Entwickler von HPE Aruba Networking haben 34 Sicherheitslücken in ArubaOS-CX geschlossen.
www.heise.de
September 4, 2026 at 5:32 AM
HPE patched 34 CVEs in ArubaOS-CX, including critical unauthenticated RCE flaws that could impact enterprise switches. The update fixes over 150 issues; no in-the-wild exploitation reported. #HPE #ArubaOSCX #CVE202673749
HPE Patches Critical RCE Vulnerabilities In AOS-CX
Hewlett Packard Enterprise (HPE) has released patches for 34 CVEs in Aruba Networking ArubaOS-CX, including critical remote code execution flaws that could let an unauthenticated attacker compromise enterprise switches. The update fixes more than 150 issues across multiple versions, and HPE says it is not aware of any of the vulnerabilities...
www.hendryadrian.com
September 5, 2026 at 4:15 AM
🟠 HOCH · Aruba Networks ArubaOS-CX: mehrere Schwachstellen

NCSC-NL
Aruba Networks ArubaOS-CX: mehrere Schwachstellen
NCSC-NL meldet mehrere Schwachstellen in Aruba Networks ArubaOS-CX mit dem Schweregrad hoch. Die vollständige Beschreibung mit betroffenen Versionen und empfohlenen Maßnahmen steht beim NCSC-NL.
www.neonotu.com
September 4, 2026 at 4:08 AM