hpe has 10 CVEs on record. 5 were published in the last 90 days. The busiest recent month was March 2026 with 5. The median CVSS is 8.8 (high), with 2 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-77 (4). Most affected products: arubaos-cx (9), autopass_license_server (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.8
- Publish → KEV
- —
- Last 90 days
- 5 prev 0
Products
- arubaos-cx 9
- autopass_license_server 1
Worst active — by depth score
CVE-2026-23813Critical· 9.8A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls66CVE-2026-23600Critical· 9.8A remote authentication bypass vulnerability exists in HPE AutoPass License Server (APLS).54CVE-2026-23814High· 8.8A vulnerability in the command parameters of a certain AOS-CX CLI command could allow a low-privilege authenticated remote attacker to inject malicious commands resulting in unwanted behavior.49CVE-2026-73753High· 8.8Exploitation through affected command-line operations could allow an authenticated low-privileged user to execute arbitrary commands as a privileged user on the underlying operating system.48CVE-2026-73751High· 8.8An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system.48
hpe vulnerabilities
CVEs affecting hpe, newest first. Open any entry for full detail, references, and exploit status.
10 CVEsRSS
CVE-2026-73751High· 8.8An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system.
An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system.
CVE-2026-73750High· 8.8Vulnerabilities exist in the authentication module that may improperly process malformed or truncated input
Vulnerabilities exist in the authentication module that may improperly process malformed or truncated input. An authenticated remote attacker could exploit these vulnerabilities by providing specially crafted input from a compromised or …
CVE-2026-73778High· 8.1A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access
A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthenticated remote attacker could exploit this vulnerability on a device in its factory-default or post-ZTP state be…
CVE-2026-73763High· 7.1A vulnerability exists in a management component that could allow an unauthenticated adjacent attacker to execute arbitrary commands
A vulnerability exists in a management component that could allow an unauthenticated adjacent attacker to execute arbitrary commands. Successful exploitation could result in remote execution of arbitrary commands in the context of the af…
CVE-2026-73753High· 8.8Exploitation through affected command-line operations could allow an authenticated low-privileged user to execute arbitrary commands as a privileged user on the underlying operating system.
Exploitation through affected command-line operations could allow an authenticated low-privileged user to execute arbitrary commands as a privileged user on the underlying operating system.
CVE-2026-23816High· 7.2A vulnerability in the command line interface of AOS-CX Switches could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.
A vulnerability in the command line interface of AOS-CX Switches could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.
CVE-2026-23815High· 7.2A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote attacker with high privileges to perform command injection
A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute unauthorized comma…
CVE-2026-23814High· 8.8A vulnerability in the command parameters of a certain AOS-CX CLI command could allow a low-privilege authenticated remote attacker to inject malicious commands resulting in unwanted behavior.
A vulnerability in the command parameters of a certain AOS-CX CLI command could allow a low-privilege authenticated remote attacker to inject malicious commands resulting in unwanted behavior.
CVE-2026-23813Critical· 9.8PoCA vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls
A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable res…
CVE-2026-23600Critical· 9.8A remote authentication bypass vulnerability exists in HPE AutoPass License Server (APLS).
A remote authentication bypass vulnerability exists in HPE AutoPass License Server (APLS).