securityonline.info 7 Oct 2026, 02:09 UTC

HPE Patches Critical AOS-Switch Flaws That Could Expose Networks

HPE Patches Critical AOS-Switch Flaws That Could Expose Networks

HPE Networking has issued patches for nine vulnerabilities in its AOS-Switch (AOS-S). Six of these are categorised as Critical, with the most severe allowing an unauthenticated attacker to execute code remotely or bypass authentication. The advisory notes that AOS-Switch is widely used in enterprise networks, meaning an attacker gaining control could monitor, redirect, or otherwise disrupt traffic. The affected releases include AOS-S 16.11.0031 and earlier, with all issues fixed in 16.11.0032 or later.

HPE says there is no confirmed exploitation at the time of the advisory, but the breadth and potential impact prompt urgent patching.

Notable CVEs include CVE-2026-76744 (9.8) described as an unauthenticated buffer overflow that could lead to remote code execution; CVE-2026-76742 (9.8) and CVE-2026-76743 (9.8) as authentication bypass flaws in the web and management interfaces, respectively. Additional memory- and buffer-related issues—CVE-2026-76745 (9.6), CVE-2026-76746 (9.3), CVE-2026-76747 (9.1), CVE-2026-76748 (8.8), and CVE-2026-76741 (6.5)—risk information disclosure, privilege escalation, or DoS. While these were not exploited publicly at the time of writing, the bulletin emphasises the urgency of updating.

For practical response, the guidance is to upgrade to AOS-S 16.11.0032 or later. If immediate patching isn’t possible, restrict management access by placing CLI and web interfaces on a dedicated Layer 2 segment/VLAN or behind firewall policies, and enable extensive logging of user activity. Given multiple flaws require no login, the advisory urges treating the update as urgent even before evidence of active exploitation.

View full article

Article by CyberSIXT