On March 10, 2026, HPE Aruba Networking disclosed the vulnerability CVE-2026-23813 in AOS-CX – according to the vendor with a CVSS score of 9.8. An unauthenticated attacker with access to the web management interface can bypass authentication and, according to the vendor, reset the admin password under certain conditions. The result is full control over the switch: VLANs, ACLs, mirror ports, routing – everything an administrator can do. The same advisory also fixed three command injection vulnerabilities rated High (CVE-2026-23814, -23815, -23816).
The good news: there is currently no known exploitation, no public exploit code, and no entry in CISA’s KEV catalog. That is precisely why now is the right time to act – while the window between disclosure and the first attack attempts still belongs to you. Experience with comparable management-plane flaws shows that this window rarely stays open for long.
The pattern is not new: back in June 2025, HPE closed an authentication bypass in the StoreOnce backup appliances with CVE-2025-37093 (CVSS 9.8) – also critical, also without known exploitation, also in the management plane. Whether switch or backup appliance: the management access of infrastructure components is repeatedly the weakest link and deserves the same hardening as any exposed system.
Who is affected
Affected are AOS-CX switches of the CX 4100i, 6000, 6100, 6200F, 6300, 6400, 8320, 8325, 8360, 8400, 9300, and 10000 series – in other words, practically the entire current campus and data center portfolio, from the access switch on the floor to the core. HPE provides fixed versions per branch: AOS-CX 10.17.1001, 10.16.1030, 10.13.1161, and 10.10.1180.
The precondition for attack is reachability of the web management. Anyone who has cleanly placed their management interfaces in a separate network has already drastically reduced exploitability – anyone who runs the web UI reachable from the production or client network should treat the flaw as acute.
What to do now
- Clarify your inventory: Which AOS-CX switches run on which version branch, and from where is their web management reachable?
- Patch per branch: to 10.17.1001, 10.16.1030, 10.13.1161, or 10.10.1180 – in the next planned maintenance window, not eventually.
- Isolate management access: Switch and appliance management belongs in a dedicated management VLAN or its own firewall zone – never in untrusted networks and certainly not on the internet. That is the one measure that also works against the next flaw of this kind.
- Restrict access: Limit web UI reachability to admin networks via ACLs; disable management services that are not needed.
- Check StoreOnce as well: Bring backup appliances to version 4.3.11 or newer – in a ransomware case, the backup infrastructure is your last line of defense.
- Stay in control: Centrally log and alert on unexpected admin password changes and configuration changes on switches.
How sector7 helps
As an owner-led systems integrator with HPE certification, we plan and run the patch rollout across your entire switch landscape – including clean separation of the management networks. Our 24/7 NOC monitoring reports configuration and status changes to your infrastructure around the clock, and with our Veeam backup practice we make sure the backup layer is hardened as well. All at flat monthly rates.
Sources
- HPE Security Bulletin HPESBNW05027: https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05027en_us&docLocale=en_US
- SecurityWeek on the AOS-CX advisory (2026-03-14): https://www.securityweek.com/critical-hpe-aos-cx-vulnerability-allows-admin-password-resets/
- SecurityWeek on CVE-2025-37093 (StoreOnce, June 2025): https://www.securityweek.com/hpe-patches-critical-vulnerability-in-storeonce/