HPE patches critical ArubaOS-CX remote code execution flaw

HPE Patches Critical Flaw in ArubaOS-CX Network Operating System

A critical vulnerability has been discovered in Hewlett Packard Enterprise’s (HPE) ArubaOS-CX network operating system, which could allow unauthenticated remote attackers to execute malicious code with elevated privileges. The flaw, tracked as CVE-2026-73749, is a buffer overflow that can be exploited by sending specially crafted packets to an affected daemon process.

The vulnerability affects various versions of the ArubaOS-CX operating system, including 10.18.0001 and earlier, 10.17.1021 and earlier, and 10.16.1051 and earlier. HPE has released patches for these versions, urging customers to upgrade to a fixed release as soon as possible.

ArubaOS-CX is the network operating system used by large businesses, government agencies, universities, healthcare organizations, data centers, and service providers. The operating system is typically used on enterprise-grade network switches, which are critical components of modern networks. An attacker who exploits this vulnerability could gain unauthorized access to sensitive information, disrupt services, or even take control of the entire network.

The vulnerability was discovered as part of HPE’s ongoing efforts to identify and fix security flaws in its products. The company has released a bulletin that provides more details about the flaw, including affected release branches and fixes. However, it’s worth noting that some versions of ArubaOS-CX have reached End of Maintenance (EOM), which means they only receive patches for internally discovered critical issues.

In addition to the critical vulnerability, HPE’s security bulletin also covers a set of 23 other security vulnerabilities, some with high severity ratings. These flaws include issues such as denial-of-service, arbitrary command execution, and unauthorized access to sensitive information. While these vulnerabilities are not as severe as the critical flaw, they still pose a significant risk to organizations that use ArubaOS-CX.

To mitigate this risk, HPE strongly encourages customers to upgrade to one of the fixed releases listed in the bulletin. However, it’s essential for organizations to also take proactive steps to secure their networks and systems. This includes regularly updating software and firmware, implementing robust security controls, and conducting regular vulnerability assessments and penetration testing.

In conclusion, the discovery of this critical flaw in ArubaOS-CX is a stark reminder of the importance of staying up-to-date with the latest security patches and best practices. Organizations that use HPE’s network operating system should take immediate action to patch their systems and ensure they are protected against potential threats. By taking proactive steps to secure their networks, organizations can minimize the risk of a cyberattack and protect their sensitive information.


Source: Bleeping Computer — 2026-09-03