Hewlett Packard Enterprise fixes critical authentication bypass in Aruba AOS-CX
2026-03-11T14:51:52Z•5f666b65f25318e4e6970ddb8613b81bb7e6f342c197b230e23d58d7a3f102f4
2fa-phishingapt28aruba-aos-cxasus-routersaurainspectorbeardshellbotnetcisa-kevcovenantcredential-exfiltrationcritical-vulnerabilitycve-2026-23813data-breachericssonfbi-alertfortigatehpekadnapmicrosoft-patch-tuesdaymisconfiguration-scanningphishingsalesforcetycoon
What happened
Multiple high‑impact vulnerabilities and active campaigns were reported: HPE patched a critical authentication bypass in Aruba AOS‑CX (CVE‑2026‑23813, CVSS 9.8) that allows admin password resets; attackers are exploiting FortiGate devices to exfiltrate configurations and credentials; and the KadNap botnet has compromised 14,000+ edge devices (mostly ASUS routers) to act as a stealth proxy. Additional notable items include Microsoft’s March Patch Tuesday (84 fixes), CISA additions to the Known Exploited Vulnerabilities catalog, long‑running APT28 espionage using BEARDSHELL and COVENANT, mass‑sc
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 5f666b65f25318e4e6970ddb8613b81bb7e6f342c197b230e23d58d7a3f102f4
- Enrichment time
- 2026-03-11T14:51:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.