HPE Aruba Networking has patched CVE-2026-73749, a critical buffer-overflow flaw in ArubaOS-CX that lets an unauthenticated remote attacker send crafted packets to a vulnerable daemon and execute code with elevated privileges on affected CX-series switches. Fixed releases include AOS-CX 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, and 10.10.1181; the 10.10.x branch is end of support and receives limited remediation.
The associated security bulletin also addresses 23 additional flaws, including command execution, arbitrary file write, authentication-bypass, privilege-escalation, denial-of-service, stored-XSS, CSRF, and predictable-default-password issues. HPE reports no known exploitation or public proof-of-concept for the disclosed vulnerabilities, but administrators should promptly upgrade to supported fixed releases; where patching is delayed, restrict management web-interface access to approved IP addresses.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
HPE disclosed and released fixes for CVE-2026-73749, a critical unauthenticated remote code-execution flaw, along with 23 additional ArubaOS-CX vulnerabilities affecting enterprise switches. Fixed releases include AOS-CX 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, and the limited-maintenance 10.10.1181 release.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
7 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourceacn.gov.it
Open sourcescworld.com
Open sourcesecurityweek.com
Open sourcesocradar.io
Open sourcebleepingcomputer.com
Open sourceheise.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.