Junglewise Threat Intelligence

CVE-2026-73776: HPE AOS-CX signature verification bypass in CLI

CVE-2026-73776 · Severity: high · CVSS 7.9 · Published 2026-09-01

Vendors: Hpe.

Executive brief

HPE AOS-CX is a network operating system used in enterprise switches and routing equipment. A signature verification bypass in the command-line interface allows authenticated administrators to execute arbitrary code on the underlying operating system, potentially compromising network infrastructure and data flows through affected devices.

Technical details

A signature verification bypass vulnerability exists in the command-line interface (CLI) of HPE AOS-CX. The vulnerability allows an authenticated administrative user to circumvent code signing checks, enabling execution of arbitrary code on the underlying operating system. Exploitation requires administrative privileges and certain pre-conditions outside the attacker's control. The attack vector is local/adjacent network access through the CLI. Patches are expected from HPE via their support portal.

Affected products

  • HPE AOS-CX

Timeline

  • 2026-09-01: disclosed
  • other: Not reported as exploited in the wild as of publication date

References