Particle.news
Download on the App Store

HPE Patches Critical RCE Flaw in ArubaOS‑CX Switch Software

HPE is urging customers to upgrade to fixed ArubaOS‑CX releases to block an unauthenticated remote‑code execution vulnerability.

Overview

  • HPE published a consolidated security bulletin in early September that fixes a critical buffer‑overflow tracked as CVE‑2026‑73749 which can let unauthenticated attackers send crafted packets to a daemon and run code with elevated privileges.
  • The company released patched builds across five AOS‑CX branches — 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190 and 10.10.1181 — and grouped many related bugs under single CVE entries to cover more than 150 underlying flaws.
  • The updates address a total of 34 CVEs, including 22 high‑severity flaws that can cause denial‑of‑service, arbitrary command execution, authentication bypass, privilege escalation and information disclosure.
  • HPE says most issues were found internally and that it is not aware of active exploitation or public proof‑of‑concept exploits at the time of publication, but it strongly recommends immediate upgrades and tighter controls on web and CLI management access.
  • Organizations using End‑of‑Maintenance releases such as 10.10.1181 should note limited support and must isolate management interfaces to dedicated VLANs or firewall‑controlled segments and enable logging to reduce risk and aid detection.