Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution.
Tracked as CVE-2026-73749, the security issue is a buffer overflow that allows unauthenticated remote attackers to send specially crafted packets to an affected daemon process, achieving code execution with elevated privileges.
“Multiple vulnerabilities exist in a daemon of ArubaOS-CX that may allow for improper processing of malformed input,” reads HPE’s bulletin.
“An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service.”
Affected release branches and fixes listed in the bulletin are:
10.18.0001 → upgrade to 10.18.1002+
10.17.1021 and earlier → 10.17.1030+
10.16.1051 and earlier → 10.16.1060+
10.13.1180 and earlier → 10.13.1190+
10.10.1180 and earlier → 10.10.1181+
... continue reading