A critical vulnerability, CVE-2026-23813, affects the web-based management interface of HPE Aruba Networking AOS-CX switches. According to the NIST description and HPE advisory, an unauthenticated remote actor can circumvent authentication controls in the web management UI; in some cases this may allow the attacker to reset the administrative password. The issue is rated CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and poses a high risk of administrative takeover, unauthorized configuration changes, and full device compromise. Administrators should consult the vendor advisory for the exact list of affected AOS-CX firmware/software versions and available patches or mitigations.
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.
References:

