Hewlett Packard Enterprise fixes critical authentication bypass in Aruba AOS-CX

2026-03-11T14:51:52Z5f666b65f25318e4e6970ddb8613b81bb7e6f342c197b230e23d58d7a3f102f4
2fa-phishingapt28aruba-aos-cxasus-routersaurainspectorbeardshellbotnetcisa-kevcovenantcredential-exfiltrationcritical-vulnerabilitycve-2026-23813data-breachericssonfbi-alertfortigatehpekadnapmicrosoft-patch-tuesdaymisconfiguration-scanningphishingsalesforcetycoon

What happened

Multiple high‑impact vulnerabilities and active campaigns were reported: HPE patched a critical authentication bypass in Aruba AOS‑CX (CVE‑2026‑23813, CVSS 9.8) that allows admin password resets; attackers are exploiting FortiGate devices to exfiltrate configurations and credentials; and the KadNap botnet has compromised 14,000+ edge devices (mostly ASUS routers) to act as a stealth proxy. Additional notable items include Microsoft’s March Patch Tuesday (84 fixes), CISA additions to the Known Exploited Vulnerabilities catalog, long‑running APT28 espionage using BEARDSHELL and COVENANT, mass‑sc

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
5f666b65f25318e4e6970ddb8613b81bb7e6f342c197b230e23d58d7a3f102f4
Enrichment time
2026-03-11T14:51:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Hewlett Packard Enterprise fixes critical authentication bypass in Aruba AOS-CX · Baitaphish