ArubaOS-CX CVE-2026-73749: Critical Unauthenticated RCE and Fixed Versions


HPE Networking disclosed CVE-2026-73749 on September 1, 2026, a critical set of buffer-overflow vulnerabilities in an AOS-CX daemon that can be reached by an unauthenticated remote attacker. HPE states that specially crafted packets sent to the affected service can lead to remote code execution with elevated privileges. The vendor assigns a CVSS v3.1 base score of 9.8 with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

The affected release bands are AOS-CX 10.18.0001, 10.17.1021 and earlier, 10.16.1051 and earlier, 10.13.1180 and earlier, and 10.10.1180 and earlier. HPE lists fixed floors of 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, and 10.10.1181 respectively.

The same security bulletin, HPESBNW05134, covers 34 CVEs across AOS-CX. CVE-2026-73749 is the only Critical-severity item in the advisory and is the clearest immediate patching priority because its published attack path requires no authentication, no user interaction and low attack complexity. HPE also recommends restricting CLI and web management to a dedicated Layer 2 segment or VLAN and applying Layer 3-or-higher firewall controls while upgrades are being scheduled.

CVE-2026-73749 at a glance

Item Detail
Vendor HPE Networking
Product ArubaOS-CX / AOS-CX
Advisory HPESBNW05134
Publication date September 1, 2026
CVE CVE-2026-73749
Vulnerability class Buffer-overflow vulnerabilities in an AOS-CX daemon
Attack vector Network
Authentication required None
User interaction None
Attack complexity Low
Impact Remote code execution with elevated privileges
CVSS v3.1 9.8 Critical
CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Discovery HPE Networking internal security research
Public exploit status at advisory release HPE reported no public discussion or exploit code targeting the listed vulnerabilities
Primary remediation Upgrade to a fixed AOS-CX release

The bulletin describes the vulnerable component only as a daemon that improperly processes malformed input. HPE's public advisory provides no daemon name or packet format for CVE-2026-73749. For remediation planning, the running AOS-CX release is the primary exposure boundary published by the vendor.

Affected and fixed AOS-CX versions

HPE publishes one fixed floor for each release train covered by the advisory.

AOS-CX branch Affected versions Fixed version / minimum
10.18 10.18.0001 10.18.1002+
10.17 10.17.1021 and earlier 10.17.1030+
10.16 10.16.1051 and earlier 10.16.1060+
10.13 10.13.1180 and earlier 10.13.1190+
10.10 10.10.1180 and earlier 10.10.1181+

Administrators should inventory the exact installed image on every CX switch and map it to this table before the maintenance window. A branch label alone is insufficient because the fixed build is a specific point release within each maintained train.

The 10.10 branch needs additional planning

HPE marks 10.10.x as End of Maintenance. The vendor states that, because of the branch's age and complexity, only internally identified Critical-severity vulnerabilities were addressed there. HPE also states that End-of-Maintenance versions are presumed affected unless explicitly excluded and recommends moving deployments to a supported software release.

That makes 10.10.1181 a tactical fix floor for CVE-2026-73749, while a supported release train is the stronger long-term target for systems that can be upgraded beyond 10.10.

Why CVE-2026-73749 is high priority

The published CVSS vector explains the operational risk directly:

  • AV:N — Network attack vector: the vulnerable service can be reached over a network path.
  • AC:L — Low attack complexity: the score assumes no unusual race condition or complex environmental prerequisite.
  • PR:N — No privileges required: an attacker does not need an authenticated account.
  • UI:N — No user interaction: exploitation does not depend on an administrator opening a file or clicking a link.
  • C:H / I:H / A:H: HPE scores successful exploitation as capable of high confidentiality, integrity and availability impact.

AOS-CX commonly sits in campus and data-center switching roles where compromise can affect network availability, segmentation and administrative control. The combination of unauthenticated reachability and elevated code execution therefore justifies prioritizing the fixed release over ordinary maintenance-cycle deferral.

HPESBNW05134 covers a wider AOS-CX security batch

CVE-2026-73749 is part of a broader September AOS-CX update. HPE's advisory references 34 CVEs, spanning remote code execution, command injection, authentication and authorization bypass, arbitrary file write, privilege escalation, information disclosure, cross-site scripting, SSRF and denial of service.

Several of the higher-severity companion vulnerabilities are relevant when deciding whether to treat this as a single-CVE patch or a broader security maintenance event:

CVE Severity HPE-described issue
CVE-2026-73749 Critical, 9.8 Unauthenticated buffer overflow leading to RCE
CVE-2026-73750 High, 8.8 Authenticated buffer overflow in API endpoint; possible code execution
CVE-2026-73751 High, 8.8 Authenticated command injection through web management
CVE-2026-73752 High, 8.8 Unauthenticated arbitrary file write that can lead to RCE
CVE-2026-73753 High, 8.8 Authenticated command injection through CLI operations
CVE-2026-73782 High, 8.8 Unauthenticated format-string issue leading to RCE
CVE-2026-73779 High, 8.2 Authentication bypass affecting integrity and information exposure
CVE-2026-73778 High, 8.1 Predictable factory-default password condition during initial setup
CVE-2026-73777 High, 8.1 Authorization bypass in an API endpoint

The shared fixed-version table in HPESBNW05134 means an upgrade planned for CVE-2026-73749 also moves the switch onto the vendor's remediated build for the advisory set applicable to that branch.

Mitigation while an upgrade is scheduled

HPE recommends reducing management-plane exposure by placing the CLI and web-based management interfaces on a dedicated Layer 2 segment or VLAN, applying firewall policies at Layer 3 and above, and enabling accounting controls that track user activity and resource usage.

These controls are useful for reducing reachable attack surface and improving visibility during the maintenance interval. The vendor's resolution section still points to the fixed AOS-CX releases as the remediation path.

A practical interim checklist is:

  1. Identify every Aruba CX switch and record its exact AOS-CX image.
  2. Compare each image with the affected/fixed table above.
  3. Restrict management access to dedicated administrative networks.
  4. Apply firewall rules so management services are reachable only from approved administration sources.
  5. Confirm accounting and administrative activity logging are enabled and retained.
  6. Prepare the vendor-supported image for the correct hardware and branch.
  7. Back up the running configuration and document rollback prerequisites before the change window.

Upgrade and verification workflow

1. Build an exact inventory

Collect the hardware model, active software image, standby image where applicable, boot configuration and current redundancy state. In stacked, VSX or other redundant deployments, map the vendor-recommended upgrade procedure to the topology before changing either peer.

2. Choose the correct fixed floor

Use the release train already deployed only when it remains a supported operational target. The minimum fixed versions from HPE are:

  • 10.18.1002
  • 10.17.1030
  • 10.16.1060
  • 10.13.1190
  • 10.10.1181

A newer supported maintenance release within the same approved train may be preferable when it includes subsequent reliability or security fixes.

3. Validate image and platform compatibility

Use the HPE Networking Support Portal and the release notes for the selected build to confirm hardware support, upgrade-path requirements, boot-space requirements and any feature-specific limitations relevant to the environment.

4. Protect configuration and recovery paths

Export the active configuration and confirm console or out-of-band management access before starting the change. Core and aggregation switches deserve explicit recovery planning because a failed boot or incompatible image can affect broad portions of the network.

5. Upgrade according to the topology

Follow the platform-specific upgrade procedure for standalone, stacked or redundant systems. Where the network design supports staged upgrades, verify control-plane and forwarding stability after each step before progressing to the next device.

6. Verify the running image after reboot

Confirm that the active image is at or above the HPE fixed floor for that branch. Also verify interface state, routing adjacencies, VLAN operation, link aggregation, redundancy, management reachability and telemetry after the switch returns to service.

7. Review logs around the exposure window

HPE reported no public discussion or exploit code targeting the listed vulnerabilities as of the advisory release. Organizations with high-value switching infrastructure should still review administrative logs, unexpected restarts, crash artifacts, configuration changes and unusual management-plane traffic covering the period before patching.

Exposure priorities by deployment role

Patch order should reflect both vulnerability severity and the network role of each device.

Highest priority generally includes internet-reachable or broadly reachable management paths, core/distribution switches, data-center fabric roles, infrastructure carrying privileged administration networks, and devices where compromise would weaken segmentation between security zones.

Next priority includes access-layer switches with tightly restricted management paths and strong administrative segmentation. Their exposure may be smaller, while the software vulnerability remains present until the fixed image is installed.

For large fleets, this role-based sequence can shorten the highest-risk exposure window while the complete AOS-CX estate moves through maintenance.

Bottom line

CVE-2026-73749 is a CVSS 9.8 unauthenticated remote-code-execution vulnerability affecting multiple AOS-CX release trains. HPE's fixed floors are 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190 and 10.10.1181. The 10.10 branch is already End of Maintenance, making migration to a supported train an important follow-on action for systems that remain there.

HPE's advisory also fixes a broad set of companion AOS-CX vulnerabilities. Network teams should treat the update as a security maintenance event for the switch fleet: restrict management exposure, upgrade to the appropriate fixed image, verify the running version and review the pre-patch exposure window on critical infrastructure.

Sources