CVE-2026-73763
massUnauthenticated Command Injection in HPE ArubaOS-CX Allows Adjacent RCE
CVE-2026-73763 is a command-injection flaw (CWE-77) in a management component of HPE's ArubaOS-CX switch operating system. An unauthenticated attacker with adjacent network access (CVSS AV:A, e.g., on the same Layer 2 segment or an adjacent network path to the management component) can submit crafted input that is passed to a command interpreter without proper neutralization, triggering execution of arbitrary commands. Successful exploitation yields remote command execution in the context of the affected utility on the switch, with high impact to confidentiality, integrity, and availability per the CVSS 8.8 score. Any organization deploying ArubaOS-CX switches is potentially affected; the source data does not specify which ArubaOS-CX version ranges are vulnerable. Exploitation status is currently quiet: there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns only a 0.3% probability of exploitation within 30 days (21st percentile).
What to do: Monitor HPE's security advisory for this CVE to identify the exact affected ArubaOS-CX releases and upgrade to a fixed release as soon as it is published. In the interim, restrict access to switch management components: place management interfaces on a dedicated management VLAN or out-of-band network, apply ACLs limiting who can reach management services, and review whether any untrusted devices share a segment with switch management planes. Defenders should also check vendor release notes and their switch inventories so affected devices can be patched quickly once HPE publishes fixed versions.
| HPE ArubaOS-CX | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability exists in a management component that could allow an unauthenticated adjacent attacker to execute arbitrary commands. Successful exploitation could result in remote execution of arbitrary commands in the context of the affected utility.
- Vendors
- hpe
- Products
- arubaos-cx
- Weakness
- CWE-77
- Vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.