HPE Patches Critical RCE Vulnerabilities in ArubaOS-CX
HPE has released security updates addressing 34 CVEs in its ArubaOS-CX network operating system, including critical remote code execution flaws.

Hewlett Packard Enterprise (HPE) has issued critical security patches for its Aruba Networking ArubaOS-CX (AOS-CX) platform, resolving a total of 34 Common Vulnerabilities and Exposures (CVEs). The updates target several versions of the network operating system, including 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, and 10.10.1181.
The most severe of these vulnerabilities, collectively tracked under CVE-2026-73749, carries a critical CVSS score of 9.8. This flaw, along with nearly two dozen other high-severity issues, stems from the improper processing of malformed input sent to an unspecified service within HPE's database-centric operating system designed for enterprise switches.
An unauthenticated attacker could exploit these critical security defects by crafting and sending malicious packets to the vulnerable service. Successful exploitation would allow the attacker to achieve remote code execution (RCE) with elevated privileges on the affected devices, posing a significant threat to network infrastructure.
In addition to the critical RCE vulnerabilities, the security updates also address 22 high-severity CVEs. These issues could lead to a range of impacts, including denial-of-service (DoS) conditions, further RCE opportunities, arbitrary command execution, arbitrary script code execution within a victim's browser, authentication bypass, privilege escalation, and information disclosure.
The remaining 11 vulnerabilities patched in this release are classified as medium-severity. These flaws present risks such as access control bypass, information disclosure, arbitrary file reads, DoS, and privilege escalation, further reinforcing the need for prompt patching.
HPE stated that the majority of these vulnerabilities were discovered internally by its dedicated security team. Importantly, the company has indicated that it is not aware of any of these specific vulnerabilities being actively exploited in the wild at the time of the advisory.
To mitigate the risk of exploitation, HPE Networking recommends restricting access to the Command Line Interface (CLI) and web-based management interfaces. This can be achieved by isolating them to a dedicated Layer 2 segment or VLAN, implementing firewall policies at Layer 3 and above, and employing robust accounting controls for tracking and logging user activities and resource usage.
This comprehensive patch release underscores the ongoing efforts by network equipment vendors to secure their platforms against sophisticated threats. Administrators of HPE ArubaOS-CX devices are strongly advised to review the advisories and apply the necessary updates to protect their networks from potential compromise.