- Total: 6 CVEs
- Severity: 1 Critical · 5 High
- Actively exploited: None confirmed
- Highest severity: 9.8 (Critical · CVSSv3) — CVE-2026-73749
- Action: Apply the latest security updates now
Notable CVEs
| CVE | CVSS (CVSSv3) | Type | Status |
|---|---|---|---|
| CVE-2026-73749 | 9.8 | CWE-284 | Not exploited |
| CVE-2026-73752 | 8.8 | CWE-22 | Not exploited |
| CVE-2026-73782 | 8.8 | CWE-134 | Not exploited |
| CVE-2026-73751 | 8.8 | Authenticated Remote Command Injection in Web-based Management Interface | Not exploited |
| CVE-2026-73750 | 8.8 | CWE-284 | Not exploited |
| CVE-2026-73778 | 8.1 | CWE-521 | Not exploited |
TL;DR
HPE Networking patched 31 vulnerabilities in AOS-CX switch software on September 1, 2026. The most severe HPE AOS-CX vulnerability, CVE-2026-73749, allows unauthenticated remote code execution. It carries a critical CVSS score of 9.8. No exploitation in the wild has been confirmed.
Why It Matters
AOS-CX powers HPE Aruba Networking enterprise switches. These devices route traffic across data centers and campuses. Therefore, a remote flaw in switch software threatens the core of many networks.
CVE-2026-73749 needs no credentials and no user interaction. As a result, any attacker with network reach to the service can strike. A successful exploit runs code with elevated privileges on the device.
How the Attack Works
The headline flaw is a set of buffer overflow bugs in an AOS-CX daemon. The advisory notes that an attacker sends “specially crafted packets to the affected service”. The daemon then mishandles that malformed input.
Consequently, memory corruption opens the door to code execution. HPE states that success could yield “remote code execution with elevated privileges”. This report withholds exploit code and packet details.
Other High-Impact Flaws
Several more critical-path issues stand out. CVE-2026-73752 is an unauthenticated arbitrary file write that can reach RCE. CVE-2026-73782 is an unauthenticated format string bug, also leading to RCE. CVE-2026-73778 lets an attacker abuse a predictable factory-default password during initial setup.
Many remaining flaws require authentication. These cover command injection, path traversal, and privilege escalation across the CLI and API.
Exploitation Status
HPE reports no active exploitation of these flaws. The advisory states it is “not aware of any public discussion or exploit code” as of release. Internal security research uncovered most issues, with two from the HPE bug bounty program. Still, the breadth and severity make fast patching wise.
Affected Versions
The flaws affect several AOS-CX branches. These include 10.18.0001 and below, 10.17.1021 and below, and 10.16.1051 and below. They also affect 10.13.1180 and below and 10.10.1180 and below. End-of-support versions should be treated as potentially affected.
Patch and Mitigation Steps
Upgrade to a fixed AOS-CX release for your branch. Fixed builds include 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, and 10.10.1181.
If You Cannot Patch Now
Restrict the CLI and web management interfaces to a dedicated VLAN. You can also apply firewall policies at layer 3 and above. In addition, enable accounting controls to log user activity. These steps reduce exposure but do not replace the update.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!