PatchSiren

Hewlett Packard Enterprise (HPE) CVE debriefs · Page 3

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Hewlett Packard Enterprise (HPE) CVE published 2026-05-12

CVE-2026-23819

A vulnerability in Aruba APs running AOS-10 and AOS-8 Instant allows unauthenticated remote attackers to execute arbitrary JavaScript code in a victim's browser within the same local network. This type of vulnerability can lead to unauthorized access and control of sensitive information. Organizations should prioritize patching to prevent potential exploitation. The CVE record was published on 2026-05-12T [truncated]

HIGH Hewlett Packard Enterprise (HPE) CVE published 2026-03-11

CVE-2026-23816

CVE-2026-23816 is a high-severity vulnerability in the command line interface of AOS-CX Switches, allowing an authenticated remote attacker to execute arbitrary commands on the underlying operating system. Hewlett Packard Enterprise (HPE) has provided an official CVE Program record and NIST NVD detail page for this vulnerability. The vulnerability has a CVSS score of 7.2 and is related to CWE-78. Vulnerab [truncated]

HIGH Hewlett Packard Enterprise (HPE) CVE published 2026-03-11

CVE-2026-23815

CVE-2026-23815 is a high-severity vulnerability in AOS-CX Switches' CLI that could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute unauthorized commands. This vulnerability requires immediate attention from defenders, particularly those responsible for AOS-CX Switches with CLI access, to assess exposure an [truncated]

HIGH Hewlett Packard Enterprise (HPE) CVE published 2026-03-11

CVE-2026-23814

A vulnerability in the command parameters of a certain AOS-CX CLI command could allow a low-privilege authenticated remote attacker to inject malicious commands resulting in unwanted behavior. This issue requires verification of command parameter validation and sanitization to prevent command injection. Network administrators and security teams should assess exposure of low-privilege authenticated remote [truncated]

CRITICAL Hewlett Packard Enterprise (HPE) CVE published 2026-03-11

CVE-2026-23813

A vulnerability in the web-based management interface of AOS-CX switches could allow an unauthenticated remote actor to bypass existing authentication controls and potentially reset the admin password. This critical authentication bypass issue requires immediate attention from network administrators and security teams to assess their exposure and take necessary actions to mitigate the vulnerability. The v [truncated]

CRITICAL Hewlett Packard Enterprise (HPE) CVE published 2026-03-02

CVE-2026-23600

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-02T15:16:32.697Z and has not been modified since then. This remote authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) and has a CVSS score of 10, indicating critical severity. The vulnerability allows attackers to bypass authentication mechanisms, potentially leading to [truncated]

Known exploited Hewlett Packard Enterprise (HPE) CVE published 2026-01-07

CVE-2025-37164

CVE-2025-37164 is a Hewlett Packard Enterprise OneView code injection vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2026-01-07. Because it is on the KEV list, organizations should treat it as a priority remediation item and apply HPE’s mitigations as soon as possible; if mitigations are not available, CISA’s guidance is to discontinue use of the product. No CVSS score was [truncated]