HPE patches 34 CVEs in Aruba AOS-CX, fixes critical RCE
Hewlett Packard Enterprise patched Aruba AOS-CX to fix 34 CVEs, including critical remote code execution flaws that let unauthenticated attackers send crafted packets to gain elevated privileges.
Hewlett Packard Enterprise released patches for ArubaOS-CX (AOS-CX) to address 34 CVEs, including multiple critical remote code execution flaws. The fixes are included in AOS-CX versions 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190 and 10.10.1181.
HPE’s advisory states the updates resolve more than 150 distinct defects across those releases, although many individual bugs are grouped under single CVE identifiers. Nearly two dozen related issues are tracked collectively as CVE-2026-73749 and carry a CVSS score of 9.8. The advisory attributes the critical defects to improper processing of malformed input sent to an unnamed service in the database-centric operating system that runs on Aruba enterprise switches.
According to the advisory, an unauthenticated attacker could exploit the defects by sending specially crafted packets to the vulnerable service and achieve remote code execution with elevated privileges. The updates also address 22 high-severity CVEs that can result in denial-of-service, remote code execution, arbitrary command execution, arbitrary script execution in a browser, authentication bypass, privilege escalation and information disclosure.
The remaining 11 CVEs are rated medium severity and can lead to access control bypasses, information disclosure, arbitrary file reads, denial-of-service and privilege escalation. The advisory notes most of the vulnerabilities were discovered internally and that HPE is not aware of evidence showing these issues have been exploited in the wild.
The advisory recommends that administrators apply the patched releases promptly. It advises restricting CLI and web-based management interfaces to a dedicated layer 2 segment or VLAN and controlling access with firewall policies at layer 3 and above, along with accounting controls to track and log user activities and resource usage.
Administrators running affected AOS-CX releases should prioritize installing the updates and review access to management interfaces. The advisory highlights enabling logging and auditing to detect unusual activity. HPE will publish further security advisories and guidance for networking customers as new patches become available.








