www.securityweek.com 9/5/2026, 12:58:54 PM · external

HPE Patches Critical ArubaOS-CX Flaw Enabling Unauthenticated RCE

HPE Patches Critical ArubaOS-CX Flaw Enabling Unauthenticated RCE
CyberSIXT Evidence Panel
Primary Source support.hpe.com
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

HEWLETT Packard Enterprise (HPE) has released patches for 34 CVEs in its Aruba Networking ArubaOS-CX platform, addressing critical remote code execution (RCE) vulnerabilities and more than 150 flaws across various versions. A significant critical issue, CVE-2026-73749, has a CVSS score of 9.8 and allows unauthenticated attackers to exploit the vulnerabilities by sending crafted packets. The updates also resolve 22 high-severity CVEs related to denial-of-service, arbitrary command execution, and more.

HPE advises restricting management interfaces to minimize exploitation risks, as it has not observed these vulnerabilities being exploited in the wild.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline