Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution by unauthenticated attackers.
The issue, tracked as CVE-2026-73749, is a buffer overflow that allows an unauthenticated remote attacker to send specially crafted packets to an affected daemon process, achieving code execution with elevated privileges.
"Multiple vulnerabilities exist in a daemon of ArubaOS-CX that may allow for improper processing of malformed input," HPE's security bulletin states. "An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service."
Affected release branches and the corresponding fixed versions are:
- 10.18.0001 → upgrade to 10.18.1002+
- 10.17.1021 and earlier → 10.17.1030+
- 10.16.1051 and earlier → 10.16.1060+
- 10.13.1180 and earlier → 10.13.1190+
- 10.10.1180 and earlier → 10.10.1181+
HPE noted that version 10.10.1181 has reached End of Maintenance and only receives fixes for internally discovered critical issues, a condition that also applies to CVE-2026-73749.
ArubaOS-CX is the operating system for HPE Aruba Networking's enterprise-grade network switches, typically used by large businesses, government agencies, universities, healthcare organizations, data centers, and service providers.
The bulletin also covers 23 other security vulnerabilities, some with high severity ratings between 8.1 and 8.8. These include flaws that could allow low-privileged authenticated attackers to execute code or cause denial of service (CVE-2026-73750), execute arbitrary commands via the web-based management interface (CVE-2026-73751), write arbitrary files to gain remote code execution (CVE-2026-73752), and execute commands as a privileged user (CVE-2026-73753). Other vulnerabilities involve format-string flaws, stored cross-site scripting, missing CSRF protections, and authentication bypasses.
HPE urges administrators using affected versions to apply the appropriate updates as soon as possible.