HPE patches critical ArubaOS-CX remote code execution flaw
Security update addresses RCE vulnerability in ArubaOS-CX network operating system

Key Takeaways
- HPE has patched a critical remote code execution vulnerability in ArubaOS-CX.
- No public exploitation was reported at the time of the patch release.
- The CVE identifier had not been assigned as of the initial report.
- Administrators should apply the released security updates promptly.
Quick answers
- What happened?
- Hewlett Packard Enterprise has released security updates to address a critical remote code execution vulnerability in the ArubaOS-CX network operating system. The patch resolves the flaw, though detailed exploitation information, CVSS scoring, and affected version specifics remain pending full disclosure.
- Which products are affected?
- ArubaOS-CX
- What should defenders do?
- HPE has released security updates to address the vulnerability. ArubaOS-CX administrators are advised to apply the latest patches to mitigate the risk of remote code execution.
Hewlett Packard Enterprise (HPE) has released security updates to address a critical remote code execution vulnerability in the ArubaOS-CX network operating system. According to reporting from BleepingComputer, the vulnerability affects ArubaOS-CX and could allow remote code execution. HPE has issued patches to mitigate the issue. At the time of reporting, no public exploitation had been observed, and the CVE identifier had not yet been formally assigned. The company has advised ArubaOS-CX administrators to apply the available security updates to protect their deployments. Further details regarding the exploitation path, affected software versions, and CVSS score are pending full disclosure.
Security Details
The vulnerability affects the ArubaOS-CX network operating system and has been addressed by HPE security updates. Specific technical details, including the exploitation vector, CVSS score, and affected versions, were not disclosed in the initial reporting.
Affected products
ArubaOS-CX
Mitigation
HPE has released security updates to address the vulnerability. ArubaOS-CX administrators are advised to apply the latest patches to mitigate the risk of remote code execution.
Sources
BleepingComputer
HPE patches critical ArubaOS-CX remote code execution flaw
Sep 3, 2026 · 18:28
Original link
Related Security News

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
The maintainers of the official MCP Python SDK disclosed a security vulnerability that could allow a malicious server to trick applications into divulging OAuth credentials. The issue affects the handling of client secrets, authorization codes, and PKCE proof keys when communicating with token endpoints.
CISA Adds Two Citrix NetScaler Vulnerabilities to Known Exploited Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. CVE-2026-88771 involves improper input validation and CVE-2026-88772 involves improper restriction of operations within the bounds of a memory buffer, both affecting Citrix NetScaler products. The additions trigger remediation requirements under Binding Operational Directive 26-04 for Federal Civilian Executive Branch agencies.


