HEWLETT Packard Enterprise (HPE) has released patches for 34 CVEs in its Aruba Networking ArubaOS-CX platform, addressing critical remote code execution (RCE) vulnerabilities and more than 150 flaws across various versions. A significant critical issue, CVE-2026-73749, has a CVSS score of 9.8 and allows unauthenticated attackers to exploit the vulnerabilities by sending crafted packets. The updates also resolve 22 high-severity CVEs related to denial-of-service, arbitrary command execution, and more.
HPE advises restricting management interfaces to minimize exploitation risks, as it has not observed these vulnerabilities being exploited in the wild.