ArubaOS-CX CVE-2026-73749: Critical Unauthenticated RCE and Fixed Versions
HPE Networking disclosed CVE-2026-73749 on September 1, 2026, a critical set of buffer-overflow vulnerabilities in an AOS-CX daemon that can be reached by an unauthenticated remote attacker. HPE states that specially crafted packets sent to the affected service can lead to remote code execution with elevated privileges. The vendor assigns a CVSS v3.1 base score of 9.8 with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
The affected release bands are AOS-CX 10.18.0001, 10.17.1021 and earlier, 10.16.1051 and earlier, 10.13.1180 and earlier, and 10.10.1180 and earlier. HPE lists fixed floors of 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, and 10.10.1181 respectively.
The same security bulletin, HPESBNW05134, covers 34 CVEs across AOS-CX. CVE-2026-73749 is the only Critical-severity item in the advisory and is the clearest immediate patching priority because its published attack path requires no authentication, no user interaction and low attack complexity. HPE also recommends restricting CLI and web management to a dedicated Layer 2 segment or VLAN and applying Layer 3-or-higher firewall controls while upgrades are being scheduled.
CVE-2026-73749 at a glance
| Item | Detail |
|---|---|
| Vendor | HPE Networking |
| Product | ArubaOS-CX / AOS-CX |
| Advisory | HPESBNW05134 |
| Publication date | September 1, 2026 |
| CVE | CVE-2026-73749 |
| Vulnerability class | Buffer-overflow vulnerabilities in an AOS-CX daemon |
| Attack vector | Network |
| Authentication required | None |
| User interaction | None |
| Attack complexity | Low |
| Impact | Remote code execution with elevated privileges |
| CVSS v3.1 | 9.8 Critical |
| CVSS vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Discovery | HPE Networking internal security research |
| Public exploit status at advisory release | HPE reported no public discussion or exploit code targeting the listed vulnerabilities |
| Primary remediation | Upgrade to a fixed AOS-CX release |
The bulletin describes the vulnerable component only as a daemon that improperly processes malformed input. HPE's public advisory provides no daemon name or packet format for CVE-2026-73749. For remediation planning, the running AOS-CX release is the primary exposure boundary published by the vendor.
Affected and fixed AOS-CX versions
HPE publishes one fixed floor for each release train covered by the advisory.
| AOS-CX branch | Affected versions | Fixed version / minimum |
|---|---|---|
| 10.18 | 10.18.0001 | 10.18.1002+ |
| 10.17 | 10.17.1021 and earlier | 10.17.1030+ |
| 10.16 | 10.16.1051 and earlier | 10.16.1060+ |
| 10.13 | 10.13.1180 and earlier | 10.13.1190+ |
| 10.10 | 10.10.1180 and earlier | 10.10.1181+ |
Administrators should inventory the exact installed image on every CX switch and map it to this table before the maintenance window. A branch label alone is insufficient because the fixed build is a specific point release within each maintained train.
The 10.10 branch needs additional planning
HPE marks 10.10.x as End of Maintenance. The vendor states that, because of the branch's age and complexity, only internally identified Critical-severity vulnerabilities were addressed there. HPE also states that End-of-Maintenance versions are presumed affected unless explicitly excluded and recommends moving deployments to a supported software release.
That makes 10.10.1181 a tactical fix floor for CVE-2026-73749, while a supported release train is the stronger long-term target for systems that can be upgraded beyond 10.10.
Why CVE-2026-73749 is high priority
The published CVSS vector explains the operational risk directly:
- AV:N — Network attack vector: the vulnerable service can be reached over a network path.
- AC:L — Low attack complexity: the score assumes no unusual race condition or complex environmental prerequisite.
- PR:N — No privileges required: an attacker does not need an authenticated account.
- UI:N — No user interaction: exploitation does not depend on an administrator opening a file or clicking a link.
- C:H / I:H / A:H: HPE scores successful exploitation as capable of high confidentiality, integrity and availability impact.
AOS-CX commonly sits in campus and data-center switching roles where compromise can affect network availability, segmentation and administrative control. The combination of unauthenticated reachability and elevated code execution therefore justifies prioritizing the fixed release over ordinary maintenance-cycle deferral.
HPESBNW05134 covers a wider AOS-CX security batch
CVE-2026-73749 is part of a broader September AOS-CX update. HPE's advisory references 34 CVEs, spanning remote code execution, command injection, authentication and authorization bypass, arbitrary file write, privilege escalation, information disclosure, cross-site scripting, SSRF and denial of service.
Several of the higher-severity companion vulnerabilities are relevant when deciding whether to treat this as a single-CVE patch or a broader security maintenance event:
| CVE | Severity | HPE-described issue |
|---|---|---|
| CVE-2026-73749 | Critical, 9.8 | Unauthenticated buffer overflow leading to RCE |
| CVE-2026-73750 | High, 8.8 | Authenticated buffer overflow in API endpoint; possible code execution |
| CVE-2026-73751 | High, 8.8 | Authenticated command injection through web management |
| CVE-2026-73752 | High, 8.8 | Unauthenticated arbitrary file write that can lead to RCE |
| CVE-2026-73753 | High, 8.8 | Authenticated command injection through CLI operations |
| CVE-2026-73782 | High, 8.8 | Unauthenticated format-string issue leading to RCE |
| CVE-2026-73779 | High, 8.2 | Authentication bypass affecting integrity and information exposure |
| CVE-2026-73778 | High, 8.1 | Predictable factory-default password condition during initial setup |
| CVE-2026-73777 | High, 8.1 | Authorization bypass in an API endpoint |
The shared fixed-version table in HPESBNW05134 means an upgrade planned for CVE-2026-73749 also moves the switch onto the vendor's remediated build for the advisory set applicable to that branch.
Mitigation while an upgrade is scheduled
HPE recommends reducing management-plane exposure by placing the CLI and web-based management interfaces on a dedicated Layer 2 segment or VLAN, applying firewall policies at Layer 3 and above, and enabling accounting controls that track user activity and resource usage.
These controls are useful for reducing reachable attack surface and improving visibility during the maintenance interval. The vendor's resolution section still points to the fixed AOS-CX releases as the remediation path.
A practical interim checklist is:
- Identify every Aruba CX switch and record its exact AOS-CX image.
- Compare each image with the affected/fixed table above.
- Restrict management access to dedicated administrative networks.
- Apply firewall rules so management services are reachable only from approved administration sources.
- Confirm accounting and administrative activity logging are enabled and retained.
- Prepare the vendor-supported image for the correct hardware and branch.
- Back up the running configuration and document rollback prerequisites before the change window.
Upgrade and verification workflow
1. Build an exact inventory
Collect the hardware model, active software image, standby image where applicable, boot configuration and current redundancy state. In stacked, VSX or other redundant deployments, map the vendor-recommended upgrade procedure to the topology before changing either peer.
2. Choose the correct fixed floor
Use the release train already deployed only when it remains a supported operational target. The minimum fixed versions from HPE are:
10.18.100210.17.103010.16.106010.13.119010.10.1181
A newer supported maintenance release within the same approved train may be preferable when it includes subsequent reliability or security fixes.
3. Validate image and platform compatibility
Use the HPE Networking Support Portal and the release notes for the selected build to confirm hardware support, upgrade-path requirements, boot-space requirements and any feature-specific limitations relevant to the environment.
4. Protect configuration and recovery paths
Export the active configuration and confirm console or out-of-band management access before starting the change. Core and aggregation switches deserve explicit recovery planning because a failed boot or incompatible image can affect broad portions of the network.
5. Upgrade according to the topology
Follow the platform-specific upgrade procedure for standalone, stacked or redundant systems. Where the network design supports staged upgrades, verify control-plane and forwarding stability after each step before progressing to the next device.
6. Verify the running image after reboot
Confirm that the active image is at or above the HPE fixed floor for that branch. Also verify interface state, routing adjacencies, VLAN operation, link aggregation, redundancy, management reachability and telemetry after the switch returns to service.
7. Review logs around the exposure window
HPE reported no public discussion or exploit code targeting the listed vulnerabilities as of the advisory release. Organizations with high-value switching infrastructure should still review administrative logs, unexpected restarts, crash artifacts, configuration changes and unusual management-plane traffic covering the period before patching.
Exposure priorities by deployment role
Patch order should reflect both vulnerability severity and the network role of each device.
Highest priority generally includes internet-reachable or broadly reachable management paths, core/distribution switches, data-center fabric roles, infrastructure carrying privileged administration networks, and devices where compromise would weaken segmentation between security zones.
Next priority includes access-layer switches with tightly restricted management paths and strong administrative segmentation. Their exposure may be smaller, while the software vulnerability remains present until the fixed image is installed.
For large fleets, this role-based sequence can shorten the highest-risk exposure window while the complete AOS-CX estate moves through maintenance.
Bottom line
CVE-2026-73749 is a CVSS 9.8 unauthenticated remote-code-execution vulnerability affecting multiple AOS-CX release trains. HPE's fixed floors are 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190 and 10.10.1181. The 10.10 branch is already End of Maintenance, making migration to a supported train an important follow-on action for systems that remain there.
HPE's advisory also fixes a broad set of companion AOS-CX vulnerabilities. Network teams should treat the update as a security maintenance event for the switch fleet: restrict management exposure, upgrade to the appropriate fixed image, verify the running version and review the pre-patch exposure window on critical infrastructure.