HPE patches critical ArubaOS-CX remote code execution flaw
CVE Tools coverage
Hewlett Packard Enterprise has released security updates for ArubaOS-CX to address CVE-2026-73749, a critical buffer overflow vulnerability that permits unauthenticated remote attackers to execute code with elevated privileges. By sending specially crafted packets to an affected daemon process, malicious actors can compromise enterprise network switches running the operating system. The vendor advises administrators to upgrade affected devices to specific fixed releases, such as version 10.18.1002 or higher, depending on their current branch.
While no active exploitation or public proof-of-concept tools have been identified yet, the bulletin also details 23 additional high-severity flaws affecting various components of the platform.