[NEW] [high] Aruba ArubaOS-CX: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in Aruba ArubaOS-CX to execute arbitrary code with elevated/root privileges, bypass security measures, obtain elevated privileges including administrator access, disclose or manipulate data, perform cross-site scripting, or cause denial-of-service conditions.
CSIRTS triage
- What
- Multiple vulnerabilities allow attackers to execute arbitrary code with elevated privileges, bypass security, escalate privileges, disclose or manipulate data, perform XSS, and cause denial-of-service.
- Who is affected
- All Aruba ArubaOS-CX deployments across the affected version range are vulnerable to one or more attack vectors.
- Urgency
- High severity; remote code execution and privilege escalation present multiple critical attack paths requiring immediate patching.
- Action
- Apply Aruba security patches for ArubaOS-CX vulnerabilities immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch ArubaOS-CX
Get an email when a new ArubaOS-CX advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3140
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMultiple vulnerabilities in HPE Aruba Networking products (02 September 2026)cert-fr-avis
- mediumCVE-2026-73783: Stack overflow vulnerabilities exist in an API endpoint of AOS-CX. Successful exploitation cou…nvd
- highCVE-2026-73782: A format string vulnerability exists in the command line interface of AOS-CX that could lead t…nvd
- highCVE-2026-73781: A vulnerability in the web-based management interface of AOS-CX could allow an authenticated r…nvd
- highCVE-2026-73780: A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions…nvd
- highCVE-2026-73779: Vulnerabilities have been identified in the operating system of AOS-CX switches that could pot…nvd
- highCVE-2026-73778: A vulnerability exists in the Credential Manager component that may allow for unauthorized adm…nvd
- highCVE-2026-73777: Vulnerabilities have been identified in the API endpoint of AOS-CX switches that could potenti…nvd
- highCVE-2026-73776: A signature verification bypass vulnerability exists in the command line interface of AOS-CX. …nvd
- highCVE-2026-73775: Vulnerabilities in the API endpoint of AOS-CX could allow a remote attacker authenticated with…nvd
- highCVE-2026-73774: A buffer overflow vulnerability exists in the underlying operating system of AOS-CX that could…nvd
- highCVE-2026-73773: An unauthenticated Denial-of-Service (DoS) vulnerability exists in the API endpoint of AOS-CX.…nvd
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] IBM i: Multiple Vulnerabilities2026-09-03
- medium[NEW] [medium] Sonatype Nexus Repository Manager: Multiple Vulnerabilities Enable Denial of Service2026-09-03
- high[NEW] [high] BigBlueButton: Multiple Vulnerabilities2026-09-03
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities2026-09-03
- medium[NEW] [medium] Red Hat Enterprise Linux (libsolv, aardvark-dns): Multiple vulnerabilities2026-09-03