CVE-2026-73770
An authenticated arbitrary file write vulnerability exists in AOS-CX. Successful exploitation could allow an authenticated malicious actor, under specific conditions outside the attacker's control and following a required action by another user, to create or modify arbitrary files and execute arbitrary commands as a privileged user on the underlying operating system.
- Published Sep 1, 2026
- CVSS 7.3 high
- 0.2% chance of exploitation in the next 30 days (EPSS)
- A fix is available