Hewlett Packard Enterprise has released patches addressing more than 150 vulnerabilities in ArubaOS-CX (AOS-CX), the operating system used across its Aruba Networking enterprise switch line, including a group of critical-severity remote-code-execution flaws.
A Critical Flaw Affecting Unauthenticated Attackers
According to HPE’s advisory, nearly two dozen individual issues are tracked collectively under CVE-2026-73749, which carries a CVSS score of 9.8. The flaws stem from improper processing of malformed input sent to an unnamed service within AOS-CX, HPE’s database-centric switch operating system. HPE says an unauthenticated attacker could exploit the defects by sending specially crafted packets to the vulnerable service, achieving remote code execution with elevated privileges.
The updates, released for AOS-CX versions 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190 and 10.10.1181, also resolve 22 high-severity vulnerabilities that could enable denial-of-service conditions, additional remote code execution, arbitrary command execution, cross-site scripting, authentication bypass, privilege escalation and information disclosure. Eleven remaining medium-severity issues cover access-control bypass, information disclosure, arbitrary file reads, denial-of-service and privilege escalation.
No Known Exploitation, but Broad Exposure
HPE says the majority of the vulnerabilities were found internally by its own security team and that it is not aware of any of them being exploited in the wild. As an interim mitigation, the company recommends restricting AOS-CX command-line and web-based management interfaces to a dedicated Layer 2 segment or VLAN, controlling access with firewall policies at Layer 3 and above, and maintaining accounting controls to track and log user activity and resource usage.
Because AOS-CX switches sit at the network layer beneath cameras, access-control panels and other connected security devices in many enterprise deployments, unpatched management-interface exposure on this class of device can translate into risk for physical security systems that depend on the same network fabric, underscoring why prompt patching of core switching infrastructure matters beyond the IT network itself.

Leave a Reply