HPE patches critical ArubaOS-CX remote code execution flaw
A serious flaw in the ArubaOS-CX network operating system that might result in remote code execution has been fixed by Hewlett Packard Enterprise (HPE).
The security flaw, known as CVE-2026-73749, is a buffer overflow that enables unauthenticated remote attackers to transmit specially constructed packets to an impacted daemon process, resulting in code execution with elevated privileges. According to HPE's advisory, a daemon of ArubaOS-CX has several vulnerabilities that could enable incorrect processing of corrupted input.
By sending specially constructed packets to the compromised service, an unauthenticated remote attacker could take advantage of these vulnerabilities. The notice lists the following affected release branches and fixes:
10.18.0001 → upgrade to 10.18.1002+
1...










