Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

HPE Patches Critical ArubaOS-CX Remote Code Execution Flaw

Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could enable remote code execution.

Tracked as CVE-2026-73749, the issue is a buffer overflow that allows unauthenticated remote attackers to send specially crafted packets to an affected daemon process. Successful exploitation could lead to code execution with elevated privileges, according to HPE’s security bulletin.

HPE said multiple vulnerabilities in an ArubaOS-CX daemon may cause improper processing of malformed input. The bulletin lists affected release branches and fixes, but the available report does not provide the individual fixed-version details.

HPE noted that AOS-CX 10.10.1181 has reached End of Maintenance (EOM). That branch receives fixes only for internally discovered critical issues, a condition that also applies to CVE-2026-73749.

The bulletin covers 23 other security vulnerabilities, including issues rated high severity from 8.1 to 8.8. HPE “strongly encourages” customers to upgrade to one of the fixed releases listed in the bulletin.

At the time of publication, HPE said it was not aware of active exploitation or publicly available proof-of-concept exploits targeting the listed flaws.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.