HPE Patches Critical RCE Vulnerabilities in AOS-CX

HPE Patches Critical RCE Vulnerabilities in AOS-CX
Hewlett Packard Enterprise (HPE) has released patches for 34 CVEs in Aruba Networking ArubaOS-CX, including critical remote code execution flaws that could let an unauthenticated attacker compromise enterprise switches. The update fixes more than 150 issues across multiple versions, and HPE says it is not aware of any of the vulnerabilities being exploited in the wild. #HPE #ArubaOS-CX #CVE-2026-73749

Keypoints

  • HPE patched 34 CVEs in Aruba Networking ArubaOS-CX.
  • Nearly two dozen flaws were grouped under CVE-2026-73749.
  • The critical bugs could enable unauthenticated remote code execution.
  • High-severity issues also include DoS, authentication bypass, and privilege escalation.
  • HPE recommends restricting CLI and web management access to reduce risk.

Read More: https://www.securityweek.com/hpe-patches-critical-rce-vulnerabilities-in-aos-cx/