HEWLETT Packard Enterprise (HPE) has released patches for 34 CVEs in its ArubaOS-CX platform, addressing critical remote code execution vulnerabilities (CVE-2026-73749 with a CVSS score of 9.8). The updates rectify over 150 flaws across various AOS-CX versions. Key issues included vulnerabilities allowing an unauthenticated attacker to exploit services for RCE with elevated privileges.
The updates also cover 22 high-severity CVEs leading to various exploitations including DoS and privilege escalation, along with 11 medium-severity flaws. HPE advises restricting management interfaces and monitoring user activities to minimize risk.