ZeroHour
Product

ArubaOS-CX

0 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

CVE-2026-73749: HPE ArubaOS-CX RCE

HPE patched CVE-2026-73749, a critical unauthenticated remote code execution flaw in ArubaOS-CX network switch software; affected devices need prompt updates.

HPE released patches for CVE-2026-73749, a critical unauthenticated remote code execution vulnerability in HPE Aruba Networking AOS-CX switch operating system. Published details are limited, but the flaw allows unauthenticated attackers to execute code on affected AOS-CX devices. Administrators running ArubaOS-CX should prioritize applying HPE's update.

SOCRadar · 11d agoVulnerabilityCVE-2026-73749

Related CVEs

  • Unauthenticated Remote Code Execution in HPE ArubaOS-CX
    HPE has disclosed multiple flaws in a daemon of ArubaOS-CX, the operating system running on Aruba's CX enterprise switches, where the service improperly processes malformed input (CWE-284, improper access control). An unauthenticated remote attacker can trigger the issue by sending specially crafted packets to the affected service, and successful exploitation yields remote code execution with elevated privileges on the switch. The 9.8 CVSS score reflects network-based attack vectors requiring no authentication, privileges, or user interaction, with high impact on confidentiality, integrity, and availability. Organizations running ArubaOS-CX switches are affected; the specific vulnerable and fixed firmware versions are not stated in the available data and must be taken from HPE's advisory. There is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.5% chance of exploitation in the next 30 days, indicating no known exploitation at this time.
    · HPE ArubaOS-CXmass

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.