CVE-2026-73752High· 8.8▾ TwilightAn unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. Successful exploitation of this vulnerability allows an attacker to write arbitrary files to the underlying operating system, which could lead to …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 22.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. Successful exploitation of this vulnerability allows an attacker to write arbitrary files to the underlying operating system, which could lead to remote code execution.
arubaos-cx < 10.10.1181arubaos-cx >= 10.13.0000, < 10.13.1190arubaos-cx >= 10.16.0000, < 10.16.1060arubaos-cx >= 10.17.0000, < 10.17.1030arubaos-cx = 10.18.0001Upgrade past the affected range:
arubaos-cx 10.17.1030Connected by shared product, vendor, weakness, or advisory.
CVE-2026-73780High· 8.3A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Request Forgery (CSRF) protection
CVE-2026-73759Medium· 6.5Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-of-service condition by sending specially crafted packets
CVE-2026-73749Critical· 9.8Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input
CVE-2026-73751High· 8.8An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system.
CVE-2026-73750High· 8.8Vulnerabilities exist in the authentication module that may improperly process malformed or truncated input
CVE-2026-73778High· 8.1A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access