CVE-2026-73774
massBuffer overflow in HPE ArubaOS-CX switches allows unauthenticated info disclosure
CVE-2026-73774 is a buffer overflow (CWE-120) in the underlying operating system of HPE Aruba's AOS-CX network switch platform. An unauthenticated attacker who can reach an affected switch over an adjacent network (the CVSS vector is AV:A, e.g., the same LAN/VLAN or a management network reachable from a compromised endpoint) can trigger the flaw by sending specially crafted packets to the system. Successful exploitation could result in limited disclosure of sensitive information, limited modification of information, and disruption of the affected system, with high availability impact reflected in the 7.6 (High) CVSS score. Any organization running affected AOS-CX switches is potentially affected, particularly where switch management interfaces are reachable from user or adjacent network segments. As of the data provided there is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns a low 0.2% probability of exploitation within 30 days, indicating no known exploitation.
What to do: Check the HPE Aruba support portal for the AOS-CX security advisory covering CVE-2026-73774 and upgrade affected switches to the fixed firmware versions it specifies. In the meantime, restrict switch management-plane access (SSH, HTTPS, SNMP) to trusted administrative VLANs using ACLs so unauthenticated adjacent devices cannot reach the management interface. Given the adjacency requirement, low EPSS, and absence of a public PoC, treat this as routine patching and hardening rather than an emergency.
| hpe arubaos-cx | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A buffer overflow vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated disclosure of sensitive information by sending specially crafted packets to the affected system. Successful exploitation of this vulnerability could result in limited disclosure or modification of information and disruption of the affected system.
- Vendors
- hpe
- Products
- arubaos-cx
- Weakness
- CWE-120
- Vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
In the news0 stories
No ingested article mentions this CVE yet.