HPE Patches Critical ArubaOS-CX Remote Code Execution Flaw
Hewlett Packard Enterprise has patched a critical unauthenticated buffer-overflow vulnerability in its ArubaOS-CX switch operating system that allows remote code execution with elevated privileges, alongside more than twenty further flaws.
Assessment
The headline issue, CVE-2026-73749, is a critical unauthenticated buffer-overflow in an ArubaOS-CX daemon that permits remote code execution via crafted packets. HPE also addressed 23 further flaws spanning CVE-2026-73750 to CVE-2026-73782, rated up to 8.8, which include command injection through the web interface, arbitrary-file-write via an API endpoint, a predictable factory-default password and authentication-bypass issues. Affected release branches span AOS-CX 10.10 through 10.18, with fixed versions named (for example 10.18.1002+, 10.17.1030+ and 10.16.1060+).
HPE reported no evidence of active exploitation or public proof-of-concept code at publication. However, ArubaOS-CX runs HPE enterprise network switches widely used by large businesses, government agencies, universities, healthcare organisations and service providers, so the patching exposure is broad.
The affected switch operating system underpins enterprise, government and university networks in Australia, including education and government sectors. Australian network operators should track HPE's security bulletin and apply the fixed AOS-CX releases as a priority. Because the flaws include an unauthenticated remote-code-execution path, treating this as an unpatched-in-the-wild risk and watching for a possible CISA KEV listing is warranted.
Sources: HPE Security Bulletin via BleepingComputer โ https://www.bleepingcomputer.com/news/security/hpe-patches-critical-arubaos-cx-remote-code-execution-flaw/