• News/
  • https://www.bleepingcomputer.com/news/security/hpe-warns-of-critical-aos-cx-flaw-allowing-admin-password-resets/

HPE warns of critical AOS-CX flaw allowing admin password resets

BleepingComputer
·
Sergiu Gatlan
·
Published Mar 10, 2026
·
Updated

Hewlett Packard Enterprise (HPE) has patched multiple security vulnerabilities in the Aruba Networking AOS-CX operating system, including several authentication and code execution issues. AOS-CX is a cloud-native network operating system (NOS) developed by HPE subsidiary Aruba Networks for the company's CX-series campus and data center switch devices. The most severe security flaw today is a critical authentication bypass vulnerability (tracked as CVE-2026-23813) that attackers without privileges can exploit in low-complexity attacks to reset admin passwords. "A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable resetting the admin password," HPE said. "HPE Aruba Networking is not aware of any public discussion or exploit code targeting these specific vulnerabilities as of the release date of the advisory." IT admins who can't immediately apply today's security updates to patch vulnerable switches can take one of the following mitigation measures: HPE has yet to find publicly available proof-of-concept exploit code or evidence that attackers are abusing the vulnerabilities in the wild. In July 2025, the company also warned of hardcoded credentials in Aruba Instant On Access Points that could allow attackers to bypass standard device authentication. One month earlier, HPE patched eight vulnerabilit...

Read full article

Affected Software

1 affected component
Hewlett Packard Enterprise Aruba Networking AOS-CX=Not specified
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical vulnerability in the HPE Aruba Networking AOS-CX operating system that allows for unauthorized administrative password resets.

2

What security implications are discussed?

The article highlights the risks associated with the vulnerability, including potential unauthorized access to network devices.

3

What products or software are affected?

The affected software is the HPE Aruba Networking AOS-CX operating system.

4

Who is the publisher of the article?

The article is published by BleepingComputer.

5

When was the vulnerability reported and patched?

The vulnerabilities were reported and patched on March 10, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203