CVE-2026-73783
published 2026-09-01CVE-2026-73783: Stack overflow vulnerabilities exist in an API endpoint of AOS-CX. Successful exploitation could allow an authenticated malicious actor to cause a…
PriorityP425medium4.9CVSS 3.1
AVNACLPRHUINSUCNINAH
EPSS
0.26%
17.4th percentile
Stack overflow vulnerabilities exist in an API endpoint of AOS-CX. Successful exploitation could allow an authenticated malicious actor to cause a denial-of-service condition on the affected system.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hewlett_packard_enterprise | aos-cx | 10.10.0000 – 10.10.1180 | — |
| hewlett_packard_enterprise | aos-cx | 10.13.0000 – 10.13.1180 | — |
| hewlett_packard_enterprise | aos-cx | 10.16.0000 – 10.16.1051 | — |
| hewlett_packard_enterprise | aos-cx | 10.17.0000 – 10.17.1021 | — |
| hewlett_packard_enterprise | aos-cx | 10.18.0000 – 10.18.0001 | — |
| hpe | arubaos-cx | <= 10.10.1180 | — |
| hpe | arubaos-cx | — | — |
| hpe | arubaos-cx | 10.13.0000 – 10.13.1180 | — |
| hpe | arubaos-cx | 10.16.0000 – 10.16.1051 | — |
| hpe | arubaos-cx | 10.17.0000 – 10.17.1021 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Stack overflow vulnerabilities exist in an API endpoint of AOS-CX.
ghsa_unreviewed·2026-09-01
CVE-2026-73783 [MEDIUM] Stack overflow vulnerabilities exist in an API endpoint of AOS-CX.
Stack overflow vulnerabilities exist in an API endpoint of AOS-CX. Successful exploitation could allow an authenticated malicious actor to cause a denial-of-service condition on the affected system.
VulDB
HPE AOS-CX up to 10.18.0001 stack-based overflow
vuldb·2026-09-01·CVSS 4.9
CVE-2026-73783 [MEDIUM] HPE AOS-CX up to 10.18.0001 stack-based overflow
A vulnerability was found in HPE AOS-CX up to 10.10.1180/10.13.1180/10.16.1051/10.17.1021/10.18.0001. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation results in stack-based buffer overflow.
This vulnerability is cataloged as CVE-2026-73783. The attack may be launched remotely. There is no exploit available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-01
Published