HPE released security updates for Aruba Networking AOS-CX to fix multiple vulnerabilities, including CVE-2026-23813, a critical flaw in the web management interface that can let a remote, unauthenticated attacker bypass authentication. In some cases, successful exploitation can also reset an administrator password and lead to full system compromise. The issue carries a CVSS 3.1 score of 9.8 and affects several release trains, including 10.17.0001 and earlier, 10.16.1020 and earlier, 10.13.1160 and earlier, and 10.10.1170 and earlier.
HPE advised customers to upgrade to fixed AOS-CX versions as soon as possible and published mitigation guidance for environments that cannot patch immediately. Recommended steps include restricting access to the management interface, disabling unnecessary HTTP(S) exposure on SVIs and routed ports, applying Control Plane ACLs for REST and HTTP management traffic, and enabling logging and continuous monitoring to detect exploitation attempts against Aruba CX switches.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
HPE released security updates for Aruba Networking AOS-CX to fix multiple vulnerabilities, including CVE-2026-23813 in the web management interface. The flaw allows a remote unauthenticated attacker to bypass authentication and, in some cases, reset the administrator password and fully compromise the system.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.