Critical CVE-2026-73749 Remote Code Execution Vulnerability in HPE ArubaOS-CX: Affected Versions, Risks, and Patch Guidance

Critical CVE-2026-73749 Remote Code Execution Vulnerability in HPE ArubaOS-CX: Affected Versions, Risks, and Patch Guidance

Executive Summary

Hewlett Packard Enterprise (HPE) has released critical security updates for its ArubaOS-CX (AOS-CX) network operating system, addressing multiple vulnerabilities, most notably the critical unauthenticated remote code execution (RCE) flaw tracked as CVE-2026-73749. These vulnerabilities impact enterprise-grade network switches that are widely deployed across large organizations, government agencies, healthcare, and data centers. At the time of writing, there is no evidence of exploitation in the wild, no public proof-of-concept code, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Technical Information

The most severe vulnerability, CVE-2026-73749, is a buffer overflow in a core daemon of ArubaOS-CX. This flaw allows unauthenticated remote attackers to send specially crafted packets, resulting in arbitrary code execution with elevated privileges. The attack vector is network-based and does not require authentication, making it highly exploitable in environments where management interfaces are exposed.

The vulnerability has been assigned a CVSS score of 9.8 (Critical). The affected versions include AOS-CX 10.18.0001 and earlier, 10.17.1021 and earlier, 10.16.1051 and earlier, 10.13.1180 and earlier, and 10.10.1180 and earlier. HPE has released patched versions for each affected branch, and customers are strongly advised to upgrade to 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, or 10.10.1181 (for EOM branches).

Other notable vulnerabilities addressed in this update include CVE-2026-73750 (authenticated DoS or code execution via malformed input), CVE-2026-73751 (authenticated RCE via web management), CVE-2026-73752 (unauthenticated adjacent-network RCE via API), CVE-2026-73753 (authenticated privilege escalation via CLI), CVE-2026-73782 (unauthenticated adjacent-network RCE via format-string in CLI), CVE-2026-73781 (stored XSS), CVE-2026-73780 (CSRF in certificate-authenticated sessions), CVE-2026-73779 (authentication bypass), CVE-2026-73778 (predictable factory-default password), and CVE-2026-73777 (API endpoint privilege escalation).

The vulnerabilities collectively enable a range of attack scenarios, including remote code execution, privilege escalation, denial of service, and unauthorized administrative access. The technical root causes span buffer overflows, input validation failures, authentication logic flaws, and insecure default configurations.

Exploitation in the Wild

As of this report, there are no confirmed reports of exploitation in the wild for CVE-2026-73749 or any of the related vulnerabilities. This is corroborated by vendor advisories, open-source threat intelligence, and the absence of public proof-of-concept code. Furthermore, a check of the CISA Known Exploited Vulnerabilities (KEV) catalog confirms that CVE-2026-73749 is not currently listed, indicating that CISA does not confirm active exploitation as of September 2026.

APT Groups using this vulnerability

No advanced persistent threat (APT) groups or criminal campaigns have been publicly linked to exploitation of these vulnerabilities at the time of writing. Open-source intelligence and MITRE ATT&CK mapping suggest that the vulnerabilities could be leveraged for initial access (T1190: Exploit Public-Facing Application), privilege escalation (T1068: Exploitation for Privilege Escalation), or lateral movement (T1210: Exploitation of Remote Services), but no attribution or targeting has been observed.

Affected Product Versions

The following ArubaOS-CX versions are affected by the critical RCE vulnerability (CVE-2026-73749) and related issues: AOS-CX 10.18.0001 and earlier (fixed in 10.18.1002+), 10.17.1021 and earlier (fixed in 10.17.1030+), 10.16.1051 and earlier (fixed in 10.16.1060+), 10.13.1180 and earlier (fixed in 10.13.1190+), and 10.10.1180 and earlier (fixed in 10.10.1181+; this branch is End of Maintenance and only receives critical fixes).

Workaround and Mitigation

Immediate action is required to mitigate risk. Organizations should upgrade to the fixed versions for their respective AOS-CX branches as soon as possible. Default credentials must be removed or secured, especially on devices in factory-default or post-ZTP state. Management interface access should be restricted to trusted networks and authorized users only. Continuous monitoring of logs and network traffic for signs of exploitation attempts, such as malformed packets or unauthorized configuration changes, is strongly recommended. Where possible, implement network segmentation to limit exposure of management interfaces.

Indicators of Compromise

Indicators of compromise are point-in-time and should be validated before enforcement. No public indicators of compromise were available at the time of writing.

References

HPE Security Bulletin: HPESBNW05134 rev.1, BleepingComputer: HPE patches critical ArubaOS-CX remote code execution flaw, SecurityWeek: HPE Patches Critical RCE Vulnerabilities in AOS-CX, RedLegg Blog: Security Bulletin: HPE Aruba Networking AOS-CX, Reddit Discussion: r/SecOpsDaily, CVE Record: CVE-2026-73749, NVD Entry: CVE-2026-73749

Rescana is here for you

Rescana provides a comprehensive third-party risk management (TPRM) platform that empowers organizations to continuously monitor, assess, and mitigate cyber risks across their supply chain and vendor ecosystem. Our platform leverages advanced threat intelligence, automation, and analytics to help you stay ahead of emerging threats and regulatory requirements. We are happy to answer any questions at info@rescana.com.