CVE-2026-73749
Affected product: HPE ArubaOS-CX โ unauthenticated buffer overflow in an ArubaOS-CX daemon
Patched version: Fixed in AOS-CX releases across branches 10.10โ10.18 (for example 10.18.1002+, 10.17.1030+ and 10.16.1060+)
Active exploitation: No โ no active exploitation or public PoCs reported at publication
Assessment
A critical unauthenticated buffer-overflow in an ArubaOS-CX daemon allows remote code execution with elevated privileges via crafted packets sent to HPE enterprise network switches. The flaw sits in the switch operating system that underpins large-business, government, university and healthcare networks, so a proof-of-concept or eventual weaponisation could give a remote attacker full control of edge switching infrastructure without credentials. HPE patched CVE-2026-73749 alongside 23 further flaws in the bundle, and the absence of public exploitation at publication is no assurance of safety for unpatched devices; Australian government and education network operators running AOS-CX should track HPE's bulletin and schedule upgrades, with priority given to internet-facing or management-exposed switches.