HPE Patches Critical RCE Vulnerabilities in ArubaOS-CX

HPE Patches Critical RCE Vulnerabilities in ArubaOS-CX

First seen 4 Sep 2026, 16:49 UTC BleepingcomputerTechtimesSecurityweeksupport.hpe.com 72.0

Article Content

Browse articles
ThreatCluster

Hewlett Packard Enterprise (HPE) has patched 24 vulnerabilities in ArubaOS-CX, including two critical remote code execution (RCE) flaws tracked as CVE-2026-73749 and CVE-2026-73782. Both vulnerabilities allow unauthenticated attackers to execute arbitrary code on affected switches without user interaction. CVE-2026-73749, a buffer overflow vulnerability, has a CVSS score of 9.8, while CVE-2026-73782 is a format-string vulnerability with a high severity rating. The vulnerabilities affect various versions of the ArubaOS-CX operating system used in enterprise-grade network switches. HPE's advisory indicates that these flaws were discovered internally, and there are currently no reports of exploitation in the wild. Network administrators are urged to apply the patches immediately to mitigate risks. The affected systems are primarily used by large organizations, government agencies, and service providers.

Key Points: • HPE patched 24 vulnerabilities in ArubaOS-CX, including two critical RCE flaws. • CVE-2026-73749 and CVE-2026-73782 allow unauthenticated remote code execution. • Network administrators must apply patches urgently to mitigate risks.

Ask AI about this cluster

Timeline

2026-09-01
HPE publishes security bulletin
HPE disclosed 24 vulnerabilities in ArubaOS-CX, including critical RCE flaws CVE-2026-73749 and CVE-2026-73782.
Techtimes
2026-09-01
CVE-2026-73749 published
CVE-2026-73749, a buffer overflow vulnerability, is published with a CVSS score of 9.8.
Bleepingcomputer
2026-09-01
CVE-2026-73782 published
CVE-2026-73782, a format-string vulnerability, is published as part of the security bulletin.
Securityweek
2026-09-01
CVE-2026-73779 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-01
CVE-2026-73780 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-01
CVE-2026-73750 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-01
CVE-2026-73781 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-01
CVE-2026-73753 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-01
CVE-2026-73778 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-01
CVE-2026-73752 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE