Hewlett Packard Enterprise has patched CVE-2026-73749, a critical buffer overflow in ArubaOS-CX that could let unauthenticated remote attackers achieve code execution with elevated privileges. The bulletin also addresses 23 additional ArubaOS-CX flaws affecting enterprise network switches used by organizations such as large businesses, government agencies, universities, healthcare organizations, data centers, and service providers. #HPE #ArubaOSCX #CVE-2026-73749
Keypoints
- CVE-2026-73749 is a critical buffer overflow in ArubaOS-CX.
- Unauthenticated remote attackers could exploit the flaw with specially crafted packets.
- The bug may lead to remote code execution with elevated privileges.
- HPE also fixed 23 other ArubaOS-CX vulnerabilities, several rated high severity.
- HPE strongly urges customers to upgrade to the fixed releases immediately.