HPE ArubaOS-CX: critical unauth RCE (CVE-2026-73749) plus high-severity management flaws
BleepingComputer (3 September 2026) reports Hewlett Packard Enterprise patched a critical buffer-overflow remote code execution issue in ArubaOS-CX, tracked as CVE-2026-73749: an unauthenticated remote attacker can send crafted packets to an affected daemon and execute code with elevated privileges. HPE security bulletin hpesbnw05134en_us lists fixed builds by branch: 10.18.0001 → 10.18.1002+; 10.17.1021 and earlier → 10.17.1030+; 10.16.1051 and earlier → 10.16.1060+; 10.13.1180 and earlier → 10.13.1190+; 10.10.1180 and earlier → 10.10.1181+ (10.10.1181 is End of Maintenance and receives only critical internal fixes). The same bulletin covers about 23 further issues; Bleeping citing HPE places several authenticated management flaws (including CVE-2026-73750/73751/73752 and related) in the high range around 8.1–8.8. WA SOC advisory 20260909002 (9 September 2026, TLP:CLEAR) covers the same CVE-2026-73749 RCE (CVSS 9.8 Critical), lists the same fixed branches, and states it has not received reports of exploitation on Western Australian Government networks at the time of writing. Upgrade AOS-CX switches to the fixed release for your branch; restrict management-plane exposure until patched.
- Product
- HPE Aruba Networking ArubaOS-CX
- Versions
- See HPE bulletin: fixed in 10.18.1002+, 10.17.1030+, 10.16.1060+, 10.13.1190+, 10.10.1181+
- CVSS
- CVE-2026-73749 9.8 Critical (WA SOC / HPE); additional management CVEs high ~8.1–8.8 per Bleeping citing HPE
- Exploited in Australia?
- unknown
- Patch to
- Upgrade to fixed AOS-CX build for your branch per hpesbnw05134en_us; limit daemon/management exposure
Primary: HPE security bulletin hpesbnw05134en_us · Vendor: HPE ArubaOS-CX bulletin · CVE: CVE-2026-73749, CVE-2026-73750 · WA SOC 20260909002 (9 Sep 2026; HPE AOS-CX RCE); also BleepingComputer 3 Sep
