VulnSea

hpe has 10 CVEs on record. 5 were published in the last 90 days. The busiest recent month was March 2026 with 5. The median CVSS is 8.8 (high), with 2 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-77 (4). Most affected products: arubaos-cx (9), autopass_license_server (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
8.8
Publish → KEV
Last 90 days
5 prev 0

Products

  • arubaos-cx 9
  • autopass_license_server 1
10
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

hpe vulnerabilities

CVEs affecting hpe, newest first. Open any entry for full detail, references, and exploit status.

10 CVEsRSS

CVE-2026-73751High· 8.8
3w ago

An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system.

An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system.

Twilighthpe · arubaos-cxEPSS 0.38%via NVD
CVE-2026-73750High· 8.8
3w ago

Vulnerabilities exist in the authentication module that may improperly process malformed or truncated input

Vulnerabilities exist in the authentication module that may improperly process malformed or truncated input. An authenticated remote attacker could exploit these vulnerabilities by providing specially crafted input from a compromised or …

Twilighthpe · arubaos-cxEPSS 0.46%via NVD
CVE-2026-73778High· 8.1
3w ago

A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access

A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthenticated remote attacker could exploit this vulnerability on a device in its factory-default or post-ZTP state be…

Twilighthpe · arubaos-cxEPSS 0.28%via NVD
CVE-2026-73763High· 7.1
3w ago

A vulnerability exists in a management component that could allow an unauthenticated adjacent attacker to execute arbitrary commands

A vulnerability exists in a management component that could allow an unauthenticated adjacent attacker to execute arbitrary commands. Successful exploitation could result in remote execution of arbitrary commands in the context of the af…

Twilighthpe · arubaos-cxEPSS 0.33%via NVD
CVE-2026-73753High· 8.8
3w ago

Exploitation through affected command-line operations could allow an authenticated low-privileged user to execute arbitrary commands as a privileged user on the underlying operating system.

Exploitation through affected command-line operations could allow an authenticated low-privileged user to execute arbitrary commands as a privileged user on the underlying operating system.

Twilighthpe · arubaos-cxEPSS 0.38%via NVD
CVE-2026-23816High· 7.2
6mo ago

A vulnerability in the command line interface of AOS-CX Switches could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.

A vulnerability in the command line interface of AOS-CX Switches could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.

Twilighthpe · arubaos-cxEPSS 0.67%via NVD
CVE-2026-23815High· 7.2
6mo ago

A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote attacker with high privileges to perform command injection

A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute unauthorized comma…

Twilighthpe · arubaos-cxEPSS 0.94%via NVD
CVE-2026-23814High· 8.8
6mo ago

A vulnerability in the command parameters of a certain AOS-CX CLI command could allow a low-privilege authenticated remote attacker to inject malicious commands resulting in unwanted behavior.

A vulnerability in the command parameters of a certain AOS-CX CLI command could allow a low-privilege authenticated remote attacker to inject malicious commands resulting in unwanted behavior.

Twilighthpe · arubaos-cxEPSS 0.56%via NVD
CVE-2026-23813Critical· 9.8PoC
6mo ago

A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls

A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable res…

Abyssalhpe · arubaos-cxEPSS 0.74%via NVD
CVE-2026-23600Critical· 9.8
6mo ago

A remote authentication bypass vulnerability  exists in HPE AutoPass License Server (APLS).

A remote authentication bypass vulnerability  exists in HPE AutoPass License Server (APLS).

Midnighthpe · autopass_license_serverEPSS 0.96%via NVD
hpe vulnerabilities (CVEs) · VulnSea