HPE Patches Critical RCE Vulnerabilities in AOS-CX
PatchArubaOS-CX (AOS-CX)Aruba Networking SwitchesOur summary
Hewlett Packard Enterprise has deployed security updates for the Aruba Networking ArubaOS-CX platform, resolving 34 vulnerabilities including a critical remote code execution flaw identified as CVE-2026-73749. The advisory covers fixes for multiple software releases, specifically 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, and 10.10.1181, addressing issues ranging from denial-of-service attacks to authentication bypasses. This specific cluster of critical defects allows unauthenticated attackers to execute arbitrary commands with elevated privileges by sending malformed input to an internal service. While HPE reports that these flaws were found internally and there is no evidence of active exploitation yet, network administrators are advised to apply the latest patches and restrict management interface access.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.