Summary
- HPE has released updates for multiple AOS-CX vulnerabilities, including the critical CVE-2026-73749 grouping.
- The critical flaws can permit unauthenticated remote code execution with elevated privileges through specially crafted packets.
- No exploitation was recorded in CISA's enrichment data, making this a patching exposure rather than a confirmed active incident.
Hewlett Packard Enterprise has issued security updates for Aruba Networking AOS-CX that address critical vulnerabilities capable of allowing an unauthenticated remote attacker to execute code with elevated privileges on affected switches.
The most serious set of defects is tracked as CVE-2026-73749 and carries a CVSS score of 9.8. HPE describes multiple buffer-overflow vulnerabilities in an AOS-CX daemon that can improperly process malformed input.
An attacker able to reach the affected service can send specially crafted packets without authentication or user interaction. Successful exploitation could result in remote code execution with elevated privileges.
HPE lists affected releases including AOS-CX 10.18.0001, 10.17.1021 and earlier, 10.16.1051 and earlier, 10.13.1180 and earlier, and 10.10.1180 and earlier. The 10.10 branch is already at end of maintenance.
The vendor has released corrected versions across supported branches. The wider September bulletin addresses dozens of CVEs and a larger number of individual defects, but CVE-2026-73749 stands out because exploitation would cross directly into privileged remote execution on network infrastructure.
CISA’s enrichment data for the CVE recorded no known exploitation at the time of assessment. That separates the disclosure from incidents in which attackers are already using a flaw in the wild.
The AOS-CX issue is consequently an exposure-management and patching problem rather than a confirmed active incident. Fixed releases exist, and the immediate operational question is which affected switches remain on vulnerable software.
Enterprise switches occupy a sensitive position because they form part of the infrastructure through which large volumes of organisational traffic move. Compromise can therefore affect a wider trust boundary than an individual endpoint or application.
Network operating systems can also follow slower maintenance cycles than user devices. Switch upgrades may require maintenance windows, redundancy testing, configuration validation, and planning around the risk of interruption to production traffic.
That caution becomes harder to sustain when a vulnerability is remotely reachable, requires no authentication, and carries a critical severity rating. An infrastructure programme designed around quarterly or longer change cycles may not match the response window created by a high-impact remote code-execution flaw.
Product lifecycle complicates the calculation further. HPE warns that versions past end of maintenance should be presumed affected unless stated otherwise, while versions past end of support may not have been assessed at all.
That makes the issue partly an asset-lifecycle problem. Hardware can remain serviceable after the software branch on which it runs has moved into reduced or discontinued security support, leaving infrastructure teams to choose between migration work and an increasingly uncertain vulnerability baseline.
There is no public evidence at present that CVE-2026-73749 is being exploited. That gives affected organisations an opportunity to identify vulnerable branches and move to fixed releases before the disclosure changes from a patching problem into an incident-response problem.
The potential consequence remains serious, however: elevated remote code execution on enterprise switching infrastructure. The speed with which organisations can respond will depend largely on whether they already have an accurate inventory of affected AOS-CX devices and supported upgrade paths.





