:

HPE PATCHES CRITICAL ARUBAOS-CX CODE EXECUTION FLAW

INDUSTRY DESK1 MIN READ
FRI, SEP 4, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Hewlett Packard Enterprise has released a patch for a critical remote code execution vulnerability in ArubaOS-CX, its network operating system used in enterprise switches and wireless controllers.

The vulnerability allows attackers to execute arbitrary code remotely on affected devices without authentication. HPE rated the flaw as critical, indicating it poses significant risk to network infrastructure. ArubaOS-CX runs on HPE's portfolio of networking hardware, including Aruba CX switches and controllers widely deployed in enterprise environments. The patch addresses the vulnerability across supported versions of the operating system. HPE advises users to apply updates immediately. The company provided patch availability through its standard support channels. Organizations running ArubaOS-CX should prioritize deployment of the fix to their network devices. Details on the specific attack vector and affected version ranges are available through HPE's security advisory. The patch is part of HPE's regular security update cycle for its networking products.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

A researcher known as Nightmare Eclipse has disclosed a CrowdStrike Falcon zero-day exploit called FalconFlank that enables privilege escalation on fully patched Windows systems. The vulnerability affects the widely-deployed endpoint protection software.

JUST NOWSecurity Desk

The U.S. military has disabled ad tracking on service members' devices after foreign adversaries exploited location data to target troops. A senator's letter confirms the action was taken in response to security threats.

JUST NOWIndustry Desk

Google has released an emergency update for Chrome to fix a high-severity zero-day vulnerability in the V8 engine currently being exploited in attacks. The update addresses this flaw plus 11 additional vulnerabilities.

2H AGOSecurity Desk

U.S. military branches have disabled advertising trackers on government-issued phones and computers following reports that location data from these trackers was being used to target American forces in the Middle East.

3H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.