HPE patches critical ArubaOS-CX remote code execution flaw

2026-09-03T19:23:20Zff4fae65c7283da1b3d6886aaab7e81305bfe84597258e4201f1f8010ba5ef95
CVE-2026-32475CVE-2026-82329CVE-2026-9586ArubaOS-CXElementor ProJFrog ArtifactoryMicrosoft WindowsPlexSangoma SwitchvoxWordPressaccount compromiseactively exploited vulnerabilitiesadministrative takeoverauthentication bypassinfostealerpatch managementransomware resilienceremote code executionreverse shellunauthenticated SQL injectionwebshell

What happened

A BleepingComputer security feed reports multiple actively exploited or critical vulnerabilities, including flaws in ArubaOS-CX, Elementor Pro, Sangoma Switchvox, WordPress backup tooling, and JFrog Artifactory. Several incidents enable unauthenticated remote code execution, administrative takeover, webshell deployment, or reverse shells. The feed also covers account breaches, infostealer risks, patch-related issues, service outages, and defensive guidance.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
ff4fae65c7283da1b3d6886aaab7e81305bfe84597258e4201f1f8010ba5ef95
Enrichment time
2026-09-03T19:23:20Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · HPE patches critical ArubaOS-CX remote code execution flaw · Baitaphish