Find notable cyber news and cases, enriched with sources, timelines, and signals.

ArubaOS-CX buffer overflow RCE (CVE-2026-73749)

Vulnerability
First reported
Last updated
Happening score
H score 30
1 unique sources, 1 articles

Summary

Hide ▲

HPE patched CVE-2026-73749, a critical ArubaOS-CX buffer overflow that can let unauthenticated remote attackers reach code execution with elevated privileges on affected switches.

Timeline

  1. 03.09.2026 21:28 2 articles · 2h ago

    HPE patches critical ArubaOS-CX buffer overflow

    Initial Disclosure

    Hewlett Packard Enterprise (HPE) disclosed and patched CVE-2026-73749, a critical buffer overflow in ArubaOS-CX that could let unauthenticated remote attackers send specially crafted packets to an affected daemon process and achieve code execution with elevated privileges. The bulletin lists fixed releases for affected branches, including 10.18.1002+, 10.17.1030+, 10.16.1060+, 10.13.1190+, and 10.10.1181+, and notes that 10.10.1181 is End of Maintenance. HPE also said it was not aware of active exploitation or publicly available proof-of-concept exploits targeting the listed flaws.

    Show sources