HPE patches critical ArubaOS-CX flaw enabling unauthenticated remote code execution
HPE has released patches addressing multiple buffer overflow vulnerabilities in ArubaOS-CX network switch software, tracked as CVE-2026-73749. The flaws reside in a daemon that improperly processes specially crafted packets, allowing an unauthenticated remote attacker to execute arbitrary code with high privileges. Affected versions include ArubaOS-CX 10.10, 10.13, 10.16, 10.17, and 10.18. HPE advises administrators to update to the fixed release for their respective version series. As a temporary measure, the company recommends restricting access to management interfaces via dedicated VLANs or firewall policies until patches can be applied.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in