CVE-2026-73759
published 2026-09-01CVE-2026-73759: Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-of-service condition by sending specially crafted packets…
PriorityP430medium6.5CVSS 3.1
AVAACLPRNUINSUCNINAH
EPSS
0.20%
10.2th percentile
Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-of-service condition by sending specially crafted packets. Successful exploitation of these vulnerabilities results in disruption of normal operation on affected devices.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hewlett_packard_enterprise | aos-cx | 10.10.0000 – 10.10.1180 | — |
| hewlett_packard_enterprise | aos-cx | 10.13.0000 – 10.13.1180 | — |
| hewlett_packard_enterprise | aos-cx | 10.16.0000 – 10.16.1051 | — |
| hewlett_packard_enterprise | aos-cx | 10.17.0000 – 10.17.1021 | — |
| hewlett_packard_enterprise | aos-cx | 10.18.0000 – 10.18.0001 | — |
| hpe | arubaos-cx | < 10.10.1181 | 10.10.1181 |
| hpe | arubaos-cx | — | — |
| hpe | arubaos-cx | >= 10.13.0000 < 10.13.1190 | 10.13.1190 |
| hpe | arubaos-cx | >= 10.16.0000 < 10.16.1060 | 10.16.1060 |
| hpe | arubaos-cx | >= 10.17.0000 < 10.17.1030 | 10.17.1030 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
HPE AOS-CX up to 10.18.0001 denial of service
vuldb·2026-09-23·CVSS 6.5
CVE-2026-73759 [MEDIUM] HPE AOS-CX up to 10.18.0001 denial of service
A vulnerability, which was classified as critical, was found in HPE AOS-CX up to 10.10.1180/10.13.1180/10.16.1051/10.17.1021/10.18.0001. The affected element is an unknown function. The manipulation results in denial of service.
This vulnerability is cataloged as CVE-2026-73759. The attack may be launched remotely. There is no exploit available.
GHSA
Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-of-service condition by sending specially crafted packets.
ghsa_unreviewed·2026-09-01
CVE-2026-73759 [MEDIUM] Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-of-service condition by sending specially crafted packets.
Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-of-service condition by sending specially crafted packets. Successful exploitation of these vulnerabilities results in disruption of normal operation on affected devices.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-01
Published