CVE-2026-73750
Affected product: HPE ArubaOS-CX โ low-privilege authenticated command/code execution
Patched version: Fixed in versions released with HPE's 3 September 2026 ArubaOS-CX bulletin (release branches 10.10โ10.18)
Active exploitation: No โ no active exploitation or public PoCs reported at publication
Assessment
CVE-2026-73750 is one of the higher-rated flaws in HPE's 24-item ArubaOS-CX patch bundle (rated up to 8.8), covering authenticated command or code execution usable by a low-privilege account on affected switches. The web-interface command-injection variant in the wider bundle illustrates how a network operator or a low-privilege administrator account can escalate to full device compromise. While it requires authentication and is therefore less exposed than the critical unauthenticated CVE-2026-73749, it is part of the same patch cycle, so Australian switch operators should apply the complete AOS-CX bundle rather than treating any single CVE in isolation, and review local admin account posture on management interfaces.