Hewlett Packard Enterprise (HPE) has released patches addressing a critical vulnerability in the ArubaOS-CX network operating system. The flaw could allow remote attackers to execute arbitrary code on affected devices. ArubaOS-CX is a widely deployed network operating system used in enterprise switching environments. The vulnerability poses significant risk to organizations relying on HPE Aruba networking infrastructure. HPE has urged customers to apply the patches promptly to mitigate potential exploitation. No specific CVE identifier was mentioned in the article excerpt provided.
HPE has disclosed and patched 24 vulnerabilities in ArubaOS-CX, the network operating system for HPE Aruba Networking enterprise switches. The critical flaw (CVE-2026-73749) is a buffer overflow in a daemon process that allows unauthenticated remote attackers to send specially crafted packets to achieve remote code execution with elevated privileges. Additional high-severity vulnerabilities include: a management module flaw allowing denial of service or code execution by low-privileged authenticated attackers (CVE-2026-73750); a web management interface command injection via crafted input by low-privileged users (CVE-2026-73751); an unauthenticated adjacent-network API endpoint flaw allowing arbitrary file writes leading to RCE (CVE-2026-73752); a CLI command injection allowing privilege escalation (CVE-2026-73753); a format-string vulnerability in the CLI exploitable by unauthenticated adjacent-network attackers for privileged code execution (CVE-2026-73782); a stored XSS in the web management interface (CVE-2026-73781); missing CSRF protections in certificate-authenticated sessions (CVE-2026-73780); an authentication bypass allowing unauthenticated adjacent-network attackers to expose sensitive information and disrupt services (CVE-2026-73779); use of a predictable factory-default password enabling full administrative control (CVE-2026-73778); and an API endpoint access control bypass enabling privilege escalation (CVE-2026-73777). HPE was not aware of active exploitation or public proof-of-concept exploits at time of publication.
Upgrade ArubaOS-CX to the fixed versions: 10.18.1002+ for the 10.18 branch, 10.17.1030+ for 10.17 and earlier, 10.16.1060+ for 10.16 and earlier, 10.13.1190+ for 10.13 and earlier, and 10.10.1181+ for 10.10 and earlier. Note that AOS-CX 10.10.1181 has reached End of Maintenance and only receives fixes for critical internally discovered issues. HPE strongly encourages all customers to upgrade to one of the fixed releases listed in the security bulletin. Monitor network traffic to ArubaOS-CX management interfaces and API endpoints for anomalous or crafted input. Ensure factory-default passwords are changed immediately upon device deployment and prior to network exposure.