Cybersecurity
HPE patches ArubaOS-CX remote code execution flaw
Hewlett Packard Enterprise said it fixed CVE-2026-73749 in ArubaOS-CX, a buffer overflow that could let remote unauthenticated attackers run code, and published upgrade paths for affected releases.
- Hewlett Packard Enterprise said it patched CVE-2026-73749 in ArubaOS-CX.
- HPE described the issue as a buffer overflow that could let unauthenticated remote attackers send crafted packets to an affected daemon and gain code execution with elevated privileges.
- The company listed upgrade paths for affected branches, including 10.18.0001 to 10.18.1002+, 10.17.1021 and earlier to 10.17.1030+, 10.16.1051 and earlier to 10.16.1060+, 10.13.1180 and earlier to 10.13.1190+, and 10.10.1180 and earlier to 10.10.1181+.
- HPE said AOS-CX 10.10.1181 had reached end of maintenance and only received fixes for internally discovered critical issues, which it said also applied to CVE-2026-73749.
- HPE said it was not aware of active exploitation or publicly available proof-of-concept code for the listed flaws when it published the bulletin.
Hewlett Packard Enterprise said it had fixed CVE-2026-73749 in ArubaOS-CX. It said the flaw was a buffer overflow that could let an unauthenticated remote attacker send specially crafted packets to an affected daemon and execute code with elevated privileges.
The bulletin listed upgrade paths for several release branches: 10.18.0001 to 10.18.1002+, 10.17.1021 and earlier to 10.17.1030+, 10.16.1051 and earlier to 10.16.1060+, 10.13.1180 and earlier to 10.13.1190+, and 10.10.1180 and earlier to 10.10.1181+. HPE said 10.10.1181 had reached end of maintenance and only got fixes for internally discovered critical issues, which it said also covered CVE-2026-73749.
HPE also said its bulletin covered 23 other vulnerabilities with severity scores between 8.1 and 8.8. The list included issues that could allow code execution, denial of service, file writes, cross-site scripting, authentication bypass and arbitrary command execution.
HPE said it was not aware of active exploitation or public proof-of-concept code for the listed flaws when it published the bulletin. The article then ended with a promotion for The Blue Report 2026.
Named in this story
Companies
- Hewlett Packard Enterprise
- patched the flaw and issued the security bulletin
Organisations
- HPE Aruba Networking
- the HPE unit whose operating system was affected
Products and systems
- ArubaOS-CX network operating system
- the software that contained the reported vulnerability
How the source tells it
The piece was mainly a technical patch notice, with brief urgency from HPE’s upgrade warning, reassurance from its no-exploitation caveat, and a promotional footer at the end.
- urgency a strong upgrade recommendation and end-of-maintenance warning
- reassurance a no-active-exploitation, no-proof-of-concept caveat
- vendor boosterism an unrelated report promotion appended after the news copy