HPE Patches CVSS 9.8 RCE in ArubaOS-CX Switches
HPE's advisory for ArubaOS-CX covers 24 flaws, led by CVE-2026-73749 — an unauthenticated buffer overflow rated 9.8 that allows remote code execution on data center switches.

HPE has released a security advisory for ArubaOS-CX, the network operating system running its CX-series data center switches, covering 24 vulnerabilities in a single bulletin. The lead flaw is rated critical. Twenty-three more come in at high severity. None are confirmed exploited in the wild as of publication.
The critical flaw
CVE-2026-73749 is a buffer overflow in a daemon process, rated CVSS 9.8. An unauthenticated remote attacker can send specially crafted packets to trigger the overflow and execute arbitrary code with elevated privileges. No authentication is required, and no legitimate user interaction is needed.
HPE’s security bulletin hpesbnw05134en_us does not attribute the flaw to an external researcher and does not provide timeline details around discovery.
What else is in the advisory
Beyond the critical RCE, the advisory covers 23 additional vulnerabilities tracked as CVE-2026-73750 through CVE-2026-73782. HPE does not give individual CVSS scores for those 23 but rates the range at 8.1 to 8.8. The class of issues includes authentication bypass, privilege escalation, arbitrary file write, cross-site scripting, and cross-site request forgery weaknesses. None reach critical severity on their own, but a cluster of high-severity flaws in a network OS creates a meaningful attack surface even when none are chained.
Affected and patched versions
The advisory covers five actively supported ArubaOS-CX branches:
| Branch | Last Vulnerable | First Patched |
|---|---|---|
| 10.18 | 10.18.0001 | 10.18.1002 |
| 10.17 | 10.17.1021 | 10.17.1030 |
| 10.16 | 10.16.1051 | 10.16.1060 |
| 10.13 | 10.13.1180 | 10.13.1190 |
| 10.10 | 10.10.1180 | 10.10.1181 |
HPE says it “strongly encourages” customers to upgrade immediately. No workarounds are offered in place of the patch.
What to do
Check the running ArubaOS-CX version on each switch against the table above and upgrade to the corresponding patched release. The HPE bulletin links to the official firmware download portal for each branch.
For organizations running Aruba CX switches in core or distribution roles, the CVSS 9.8 rating on CVE-2026-73749 justifies out-of-cycle patching rather than waiting for a scheduled maintenance window. An unauthenticated RCE on a device that sits between server and edge segments is a serious exposure if exploitation does emerge. HPE’s current assessment is that none has appeared, but advisories of this scope tend to attract attention once they are public.
Context
Aruba’s CX product line is HPE’s modern campus and data center switching platform, distinct from the older Aruba ArubaOS (wireless) stack. CX switches are deployed broadly in enterprise environments that moved off legacy HPE ProCurve and Comware hardware. The affected version range suggests the flaw spans at least two and a half years of software branches, which is a common pattern when a vulnerability sits in a daemon inherited across releases.
Twenty-four CVEs in one advisory is not unusual for a mature network OS vendor clearing a backlog, but the presence of a 9.8 at the top makes this one worth scheduling before Q4. Aruba network gear tends to be under-represented in patch tracking tools that focus on perimeter firewalls and VPN concentrators, which is a habit that this class of vulnerability occasionally punishes.
Sources: HPE Security Bulletin hpesbnw05134en_us, BleepingComputer, NVD: CVE-2026-73749.
Found this useful? Share it.


