HPE warns of dangerous security flaws that could allow Aruba OS password resets


  • HPE fixes five vulnerabilities in Aruba AOS-CX
  • Critical bug (CVE-2026-23813) allowed administrator password reset
  • The company is urging mitigation until fixes are implemented

Hewlett Packard Enterprise (HPE) has warned its customers after discovering five vulnerabilities in its products, including one that cybercriminals could use to take over certain endpoints.

In a recently released security advisory, HPE said it addressed a critical authentication bypass flaw that can be used by unauthenticated attackers in low-complexity attacks to reset administrator passwords. The bug is now tracked as CVE-2026-23813 and has a severity score of 9.1/10 (Critical).

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top