CVE Tools

HPE Patches Critical RCE Vulnerabilities in AOS-CX

SecurityWeekBy Ionut Arghire

PatchArubaOS-CX (AOS-CX)Aruba Networking Switches

Our summary

Hewlett Packard Enterprise has deployed security updates for the Aruba Networking ArubaOS-CX platform, resolving 34 vulnerabilities including a critical remote code execution flaw identified as CVE-2026-73749. The advisory covers fixes for multiple software releases, specifically 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, and 10.10.1181, addressing issues ranging from denial-of-service attacks to authentication bypasses. This specific cluster of critical defects allows unauthenticated attackers to execute arbitrary commands with elevated privileges by sending malformed input to an internal service. While HPE reports that these flaws were found internally and there is no evidence of active exploitation yet, network administrators are advised to apply the latest patches and restrict management interface access.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store