HPE warns of critical AOS-CX flaw allowing admin password resets
ID: 2bdf1636-c37f-51b3-8efe-25c8b20418c9
STIX ID: report--2bdf1636-c37f-51b3-8efe-25c8b20418c9
Feed Name: Bleeping Computer
Hewlett Packard Enterprise patched multiple vulnerabilities in the Aruba AOS-CX network operating system, including a critical authentication bypass (CVE-2026-23813) that could allow unauthenticated attackers to reset administrator passwords. The advisory outlines mitigations (restricting management access, disabling unnecessary HTTP(S), enforcing control-plane ACLs, and logging) and notes that HPE is not aware of public exploits or active abuse; the report also references recent related HPE advisories and past vulnerabilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
