CVE Tools

HPE patches critical ArubaOS-CX remote code execution flaw

BleepingComputerBy Bill Toulas

PatchArubaOS-CX

Our summary

Hewlett Packard Enterprise has released security updates for ArubaOS-CX to address CVE-2026-73749, a critical buffer overflow vulnerability that permits unauthenticated remote attackers to execute code with elevated privileges. By sending specially crafted packets to an affected daemon process, malicious actors can compromise enterprise network switches running the operating system. The vendor advises administrators to upgrade affected devices to specific fixed releases, such as version 10.18.1002 or higher, depending on their current branch.

While no active exploitation or public proof-of-concept tools have been identified yet, the bulletin also details 23 additional high-severity flaws affecting various components of the platform.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store