HPE fixes critical RCE vulnerabilities in AOS-CX

Hewlett Packard Enterprise (HPE) has released patches for 34 CVEs in the Aruba Networking ArubaOS-CX (AOS-CX) platform, including critical severity remote code execution (RCE) flaws.

According to HPT consultativemore than 150 bugs were resolved in AOS-CX versions 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190 and 10.10.1181. Many of these bugs are tracked together under separate CVEs.

Nearly two dozen issues, collectively tracked as CVE-2026-73749 (CVSS score 9.8), were addressed with the updates.

The critical security flaws are rooted in improper handling of malformed input data sent to an unnamed service within HPE’s database-based operating system for enterprise switches.

According to the company, an unauthenticated attacker could exploit the security flaws by sending crafted packets to the vulnerable service, achieving an elevated-privilege RCE.

The fresh updates also resolve 22 high-severity CVEs that could lead to a denial of service (DoS), RCE, arbitrary command execution, arbitrary script code execution in the victim’s browser, authentication bypass, privilege escalation, and information disclosure.

Advertising. Scroll to continue reading.

The remaining 11 CVEs are all medium-severity flaws leading to access control bypass, information disclosure, arbitrary file reads, DoS, and privilege escalation.

HPE says the majority of these vulnerabilities were discovered internally by its security team, noting that it is not aware of any of them being exploited in the wild.

“To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated segment/VLAN at Layer 2 and/or controlled by firewall policies at Layer 3 and above, along with reporting controls to track and log user activities and resource usage,” the company notes.

Related: Sangoma Switchvox Vulnerabilities Exploited in the Wild

Related: VMware Workstation and Fusion updates fix critical vulnerability

Related: Capsule Security launches ‘AI Circuit Breaker’ to stop rogue agents

Related: Cisco warns of unpatched flaws in secure email, fixes critical switch vulnerabilities

Leave a Reply

Your email address will not be published. Required fields are marked *