CVE-2026-73749

Published Sep 1, 2026

Last updated 2 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-73749 is a vulnerability found in a daemon within HPE Aruba Networking AOS-CX, which is the operating system for Aruba's enterprise-grade network switches. This flaw arises from the improper processing of malformed input by the affected daemon. An unauthenticated remote attacker can exploit this vulnerability by sending specially crafted packets to the vulnerable service. Successful exploitation of CVE-2026-73749 can lead to remote code execution with elevated privileges on the affected AOS-CX switches. This vulnerability impacts the control plane of these switches, which are commonly used in campus, data center, and critical network infrastructures.

Description
Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service. Successful exploitation could result in remote code execution with elevated privileges.
Source
security-alert@hpe.com
NVD status
Analyzed
Products
arubaos-cx

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-284

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

5

  1. HPE patches critical RCE flaws in AOS-CX (CVE-2026-73749, CVSS 9.8). Update switches now. #Vulnerability #NetworkSecurity #CyberSecurity

    @chris_uk2026

    6 Sept 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. HPE Patches Critical RCE Vulnerabilities in AOS-CX (CVE-2026-73749) https://t.co/hN6bmgY4Ge

    @SecurityWeek

    5 Sept 2026

    2628 Impressions

    1 Retweet

    2 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  3. HPEのArubaOS-CXに認証不要のRCEなど34件のCVE — CVSS 9.8のCVE-2026-73749を含む修正版を公開、実悪用は未確認 https://t.co/0M7MEhjXF9

    @NEXSIGHTNEWS

    5 Sept 2026

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🔒 #CyberSecurity CVE-2026-73749: Critical RCE Cluster in HPE Aruba AOS-CX Switches — Detection a… "HPE has released security updates addressing a cluster of nearly two dozen vulnerabilities in…" 🔗 https://t.co/AsDrWXaSwz #CyberSecurity #ThreatIntel #critical #zero

    @SecurityAr58409

    5 Sept 2026

    53 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨 Critical vulnerability alert — 2 CVEs, both CVSS 9.8 CVE-2026-20212 (Cisco Nexus 9000) → Unauthenticated root-level RCE → Hits Nexus 9000 w/ Silicon One, via TCP 43210/43211 → Can crash S1HAL & reload switch CVE-2026-73749 (HPE ArubaOS-CX) → Unauthenticated RCE

    @socradar

    4 Sept 2026

    228 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  6. HPE patches CVE-2026-73749, a critical buffer overflow in ArubaOS-CX allowing unauthenticated RCE on enterprise switches. Patch immediately. #Cybersecurity #HPE #Aruba https://t.co/vy4lQ2Hdg4

    @CyberWorldOps

    4 Sept 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🚨 CYBER — HPE corrige une vulnérabilité critique dans ArubaOS-CX permettant l’exécution de code à distance sans authentification. La faille CVE-2026-73749, notée CVSS 9,8/10, touche le système d’exploitation utilisé sur de nombreux switches HPE Aruba en entrepris

    @ActuX_off

    4 Sept 2026

    20 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations