CVE Tools
Back to feed
Patch released ArubaOS-CX (AOS-CX) rce Aruba Networking Switches Hewlett Packard Enterprise network-edge

HPE Patches Critical RCE Vulnerabilities in AOS-CX

SecurityWeek·By Ionut Arghire··1 min read
CVE Tools coverage

Hewlett Packard Enterprise has deployed security updates for the Aruba Networking ArubaOS-CX platform, resolving 34 vulnerabilities including a critical remote code execution flaw identified as CVE-2026-73749. The advisory covers fixes for multiple software releases, specifically 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, and 10.10.1181, addressing issues ranging from denial-of-service attacks to authentication bypasses. This specific cluster of critical defects allows unauthenticated attackers to execute arbitrary commands with elevated privileges by sending malformed input to an internal service. While HPE reports that these flaws were found internally and there is no evidence of active exploitation yet, network administrators are advised to apply the latest patches and restrict management interface access.