Home ยท Wiki ยท Vulnerabilities & CVEs
type: vulnerability ยท created: 2026-09-04 ยท updated: 2026-09-04 ยท tags: ["cve", "vulnerability", "hpe", "arubaos-cx", "buffer-overflow", "remote-code-execution"] ยท confidence: high ยท severity: critical ยท affected_sectors: ["Technology", "Government", "Defence", "Education"] ยท au_impact: true

CVE-2026-73749

Affected product: HPE ArubaOS-CX โ€” unauthenticated buffer overflow in an ArubaOS-CX daemon

Patched version: Fixed in AOS-CX releases across branches 10.10โ€“10.18 (for example 10.18.1002+, 10.17.1030+ and 10.16.1060+)

Active exploitation: No โ€” no active exploitation or public PoCs reported at publication

Assessment

A critical unauthenticated buffer-overflow in an ArubaOS-CX daemon allows remote code execution with elevated privileges via crafted packets sent to HPE enterprise network switches. The flaw sits in the switch operating system that underpins large-business, government, university and healthcare networks, so a proof-of-concept or eventual weaponisation could give a remote attacker full control of edge switching infrastructure without credentials. HPE patched CVE-2026-73749 alongside 23 further flaws in the bundle, and the absence of public exploitation at publication is no assurance of safety for unpatched devices; Australian government and education network operators running AOS-CX should track HPE's bulletin and schedule upgrades, with priority given to internet-facing or management-exposed switches.