HPE released security updates for Aruba Networking ArubaOS-CX, fixing critical flaws that could let an attacker take over vulnerable enterprise switches without logging in. The most serious issue, CVE-2026-73749, groups nearly two dozen bugs in an unnamed service that improperly handles malformed network input; crafted packets can trigger remote code execution with elevated privileges. Fixed versions include AOS-CX 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, and 10.10.1181, and the update set also addresses 22 high-severity and 11 medium-severity CVEs.
Why it matters: Organizations using ArubaOS-CX switches should treat this as a high-priority infrastructure update because unauthenticated code execution on switching gear can expose or disrupt large parts of a network. Update affected systems and restrict CLI and web management interfaces to dedicated management networks or tightly controlled firewall rules.
Ionut Arghire
2026.09.05
100% relevant
This article establishes a distinct new story about HPE's September 2026 patch release for ArubaOS-CX, centered on CVE-2026-73749 and the broader set of 34 CVEs fixed in the platform.
← Back to all stories