Skip to content
feed: live
>_0dayNews
threat intel

HPE Patches CVSS 9.8 RCE in ArubaOS-CX Switches

HPE's advisory for ArubaOS-CX covers 24 flaws, led by CVE-2026-73749 — an unauthenticated buffer overflow rated 9.8 that allows remote code execution on data center switches.

HPE Patches CVSS 9.8 RCE in ArubaOS-CX Switches
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
kilobaudDave "Kilobaud" Ferris·Published ·2 min read

HPE has released a security advisory for ArubaOS-CX, the network operating system running its CX-series data center switches, covering 24 vulnerabilities in a single bulletin. The lead flaw is rated critical. Twenty-three more come in at high severity. None are confirmed exploited in the wild as of publication.

The critical flaw

CVE-2026-73749 is a buffer overflow in a daemon process, rated CVSS 9.8. An unauthenticated remote attacker can send specially crafted packets to trigger the overflow and execute arbitrary code with elevated privileges. No authentication is required, and no legitimate user interaction is needed.

HPE’s security bulletin hpesbnw05134en_us does not attribute the flaw to an external researcher and does not provide timeline details around discovery.

What else is in the advisory

Beyond the critical RCE, the advisory covers 23 additional vulnerabilities tracked as CVE-2026-73750 through CVE-2026-73782. HPE does not give individual CVSS scores for those 23 but rates the range at 8.1 to 8.8. The class of issues includes authentication bypass, privilege escalation, arbitrary file write, cross-site scripting, and cross-site request forgery weaknesses. None reach critical severity on their own, but a cluster of high-severity flaws in a network OS creates a meaningful attack surface even when none are chained.

Affected and patched versions

The advisory covers five actively supported ArubaOS-CX branches:

Branch Last Vulnerable First Patched
10.18 10.18.0001 10.18.1002
10.17 10.17.1021 10.17.1030
10.16 10.16.1051 10.16.1060
10.13 10.13.1180 10.13.1190
10.10 10.10.1180 10.10.1181

HPE says it “strongly encourages” customers to upgrade immediately. No workarounds are offered in place of the patch.

What to do

Check the running ArubaOS-CX version on each switch against the table above and upgrade to the corresponding patched release. The HPE bulletin links to the official firmware download portal for each branch.

For organizations running Aruba CX switches in core or distribution roles, the CVSS 9.8 rating on CVE-2026-73749 justifies out-of-cycle patching rather than waiting for a scheduled maintenance window. An unauthenticated RCE on a device that sits between server and edge segments is a serious exposure if exploitation does emerge. HPE’s current assessment is that none has appeared, but advisories of this scope tend to attract attention once they are public.

Context

Aruba’s CX product line is HPE’s modern campus and data center switching platform, distinct from the older Aruba ArubaOS (wireless) stack. CX switches are deployed broadly in enterprise environments that moved off legacy HPE ProCurve and Comware hardware. The affected version range suggests the flaw spans at least two and a half years of software branches, which is a common pattern when a vulnerability sits in a daemon inherited across releases.

Twenty-four CVEs in one advisory is not unusual for a mature network OS vendor clearing a backlog, but the presence of a 9.8 at the top makes this one worth scheduling before Q4. Aruba network gear tends to be under-represented in patch tracking tools that focus on perimeter firewalls and VPN concentrators, which is a habit that this class of vulnerability occasionally punishes.


Sources: HPE Security Bulletin hpesbnw05134en_us, BleepingComputer, NVD: CVE-2026-73749.

Found this useful? Share it.