Vulnerability
Published 2026-09-03
Verified 2026-09-19

HPE ArubaOS-CX: critical unauth RCE (CVE-2026-73749) plus high-severity management flaws

BleepingComputer (3 September 2026) reports Hewlett Packard Enterprise patched a critical buffer-overflow remote code execution issue in ArubaOS-CX, tracked as CVE-2026-73749: an unauthenticated remote attacker can send crafted packets to an affected daemon and execute code with elevated privileges. HPE security bulletin hpesbnw05134en_us lists fixed builds by branch: 10.18.0001 → 10.18.1002+; 10.17.1021 and earlier → 10.17.1030+; 10.16.1051 and earlier → 10.16.1060+; 10.13.1180 and earlier → 10.13.1190+; 10.10.1180 and earlier → 10.10.1181+ (10.10.1181 is End of Maintenance and receives only critical internal fixes). The same bulletin covers about 23 further issues; Bleeping citing HPE places several authenticated management flaws (including CVE-2026-73750/73751/73752 and related) in the high range around 8.1–8.8. WA SOC advisory 20260909002 (9 September 2026, TLP:CLEAR) covers the same CVE-2026-73749 RCE (CVSS 9.8 Critical), lists the same fixed branches, and states it has not received reports of exploitation on Western Australian Government networks at the time of writing. Upgrade AOS-CX switches to the fixed release for your branch; restrict management-plane exposure until patched.

Product
HPE Aruba Networking ArubaOS-CX
Versions
See HPE bulletin: fixed in 10.18.1002+, 10.17.1030+, 10.16.1060+, 10.13.1190+, 10.10.1181+
CVSS
CVE-2026-73749 9.8 Critical (WA SOC / HPE); additional management CVEs high ~8.1–8.8 per Bleeping citing HPE
Exploited in Australia?
unknown
Patch to
Upgrade to fixed AOS-CX build for your branch per hpesbnw05134en_us; limit daemon/management exposure

Primary: HPE security bulletin hpesbnw05134en_us · Vendor: HPE ArubaOS-CX bulletin · CVE: CVE-2026-73749, CVE-2026-73750 · WA SOC 20260909002 (9 Sep 2026; HPE AOS-CX RCE); also BleepingComputer 3 Sep

vulnerabilities network australia