HPE ArubaOS-CX security bulletin (CVE-2026-73749)
Security Patch Release
Summary
Hide ▲
Show ▼
HPE released a security bulletin for ArubaOS-CX that patches CVE-2026-73749, a buffer overflow that could let unauthenticated remote attackers reach remote code execution on affected switches. The bulletin lists fixed releases for 10.18.0001, 10.17.1021 and earlier, 10.16.1051 and earlier, 10.13.1180 and earlier, and 10.10.1180 and earlier. HPE also flagged 10.10.1181 as End of Maintenance, limiting its fix support for this critical issue.
Related Happenings
Adobe security patch release for CVE-2026-48362
Security Patch Release
H score43
First: 11.08.2026 19:50
Last: 11.08.2026 19:50
Sources 1
About this happening:
Adobe shipped a priority 1 update for ColdFusion that fixes 15 security defects, including flaws that could enable arbitrary code execution and application D...
Adobe security patch release for CVE-2026-48362
Security Patch ReleaseAbout this happening: Adobe shipped a priority 1 update for ColdFusion that fixes 15 security defects, including flaws that could enable arbitrary code execution and application D...
Veeam security patch release for CVE-2026-58073
Security Patch Release
H score39
First: 05.08.2026 17:27
Last: 05.08.2026 17:27
Sources 1
About this happening:
Veeam released Service Provider Console 9.3.0.35057 to fix four vulnerabilities in the multi-tenant backup management console. The most serious are CVE-2026-58073,...
Veeam security patch release for CVE-2026-58073
Security Patch ReleaseAbout this happening: Veeam released Service Provider Console 9.3.0.35057 to fix four vulnerabilities in the multi-tenant backup management console. The most serious are CVE-2026-58073,...
OpenWrt security patch release for CVE-2026-53921
Security Patch Release
H score37
First: 28.07.2026 15:56
Last: 28.07.2026 15:56
Sources 1
About this happening:
OpenWrt released 24.10.8 and 25.12.5 to close a critical DHCPv6 stack overflow in odhcpd, reducing the risk of root code execution on exposed routers. The...
OpenWrt security patch release for CVE-2026-53921
Security Patch ReleaseAbout this happening: OpenWrt released 24.10.8 and 25.12.5 to close a critical DHCPv6 stack overflow in odhcpd, reducing the risk of root code execution on exposed routers. The...
Linux kernel upstream security patch release for CVE-2026-53264
Security Patch Release
H score32
First: 28.07.2026 11:04
Last: 28.07.2026 11:04
Sources 1
About this happening:
Linux kernel maintainers have backported CVE-2026-53264 fixes across stable branches, closing a local privilege-escalation path that can turn a local user into root on...
Linux kernel upstream security patch release for CVE-2026-53264
Security Patch ReleaseAbout this happening: Linux kernel maintainers have backported CVE-2026-53264 fixes across stable branches, closing a local privilege-escalation path that can turn a local user into root on...
SonicWall security patch release for CVE-2026-15409
Security Patch Release
H score54
First: 15.07.2026 00:23
Last: 15.07.2026 00:23
Sources 1
About this happening:
SonicWall released hotfix security updates for SMA1000 appliances after confirming active exploitation of CVE-2026-15409 and CVE-2026-15410. The fixes are availabl...
SonicWall security patch release for CVE-2026-15409
Security Patch ReleaseAbout this happening: SonicWall released hotfix security updates for SMA1000 appliances after confirming active exploitation of CVE-2026-15409 and CVE-2026-15410. The fixes are availabl...
Timeline
-
03.09.2026 21:28 2 articles · 2h ago
HPE patches critical ArubaOS-CX remote code execution flaw
Mitigation Patch UpdateHewlett Packard Enterprise patched CVE-2026-73749 in ArubaOS-CX, a critical buffer overflow in a daemon that could let unauthenticated remote attackers send specially crafted packets and achieve code execution with elevated privileges. HPE listed fixed releases for 10.18.0001, 10.17.1021 and earlier, 10.16.1051 and earlier, 10.13.1180 and earlier, and 10.10.1180 and earlier, and said 10.10.1181 is End of Maintenance with fixes only for internally discovered, critical issues. HPE also said it was not aware of active exploitation or publicly available proof-of-concept exploits at publication time.
Show sources
- HPE patches critical ArubaOS-CX remote code execution flaw — www.bleepingcomputer.com — 03.09.2026 21:28
- HPE patches critical ArubaOS-CX remote code execution flaw — www.bleepingcomputer.com — 03.09.2026 21:28