An unauthenticated critical vulnerability (CVE-2026-23813, CVSS 9.8) in the Aruba AOS‑CX web management interface allows remote actors to reset administrator passwords.
Part of the PlainSec briefing for 2026-03-15