Skip to content
Tech News
← Back to articles

HPE patches critical ArubaOS-CX remote code execution flaw

read original more articles
Why This Matters

HPE has issued patches for a critical remote code execution vulnerability in ArubaOS-CX, which could allow attackers to compromise enterprise network switches. This highlights the ongoing importance of timely security updates to protect large-scale network infrastructure used by organizations worldwide.

Key Takeaways

Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution.

Tracked as CVE-2026-73749, the security issue is a buffer overflow that allows unauthenticated remote attackers to send specially crafted packets to an affected daemon process, achieving code execution with elevated privileges.

“Multiple vulnerabilities exist in a daemon of ArubaOS-CX that may allow for improper processing of malformed input,” reads HPE’s bulletin.

“An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service.”

Affected release branches and fixes listed in the bulletin are:

10.18.0001 → upgrade to 10.18.1002+

10.17.1021 and earlier → 10.17.1030+

10.16.1051 and earlier → 10.16.1060+

10.13.1180 and earlier → 10.13.1190+

10.10.1180 and earlier → 10.10.1181+

... continue reading