ArubaOS-CX buffer overflow RCE (CVE-2026-73749)
Vulnerability
Summary
Hide ▲
Show ▼
HPE patched CVE-2026-73749, a critical ArubaOS-CX buffer overflow that can let unauthenticated remote attackers reach code execution with elevated privileges on affected switches.
Timeline
-
03.09.2026 21:28 2 articles · 2h ago
HPE patches critical ArubaOS-CX buffer overflow
Initial DisclosureHewlett Packard Enterprise (HPE) disclosed and patched CVE-2026-73749, a critical buffer overflow in ArubaOS-CX that could let unauthenticated remote attackers send specially crafted packets to an affected daemon process and achieve code execution with elevated privileges. The bulletin lists fixed releases for affected branches, including 10.18.1002+, 10.17.1030+, 10.16.1060+, 10.13.1190+, and 10.10.1181+, and notes that 10.10.1181 is End of Maintenance. HPE also said it was not aware of active exploitation or publicly available proof-of-concept exploits targeting the listed flaws.
Show sources
- HPE patches critical ArubaOS-CX remote code execution flaw — www.bleepingcomputer.com — 03.09.2026 21:28
- HPE patches critical ArubaOS-CX remote code execution flaw — www.bleepingcomputer.com — 03.09.2026 21:28