Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Congressman says TikTok backed out of a meeting to avoid child safety questions

    September 3, 2026

    NVIDIA to acquire Hugging Face for $12.93B

    September 3, 2026

    HPE patches critical ArubaOS-CX remote code execution flaw

    September 3, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Congressman says TikTok backed out of a meeting to avoid child safety questions
    • NVIDIA to acquire Hugging Face for $12.93B
    • HPE patches critical ArubaOS-CX remote code execution flaw
    • Wallet Recovery Experts Crack $1B ETH Wallet… But Find Just $10
    • Bats carry dangerous viruses without getting sick. This may be why
    • Smulders HSM, SPIE and Scaldis help future-proof offshore wind-powered North Sea gas platform
    • The Guardian view on press freedom: to defend democracy, stand up for journalists | Editorial
    • ‘Fight through darkness, water’: Nepal survivor recounts escape from flood-hit tunnel
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, September 3
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    HPE patches critical ArubaOS-CX remote code execution flaw

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 3, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution.

    Tracked as CVE-2026-73749, the security issue is a buffer overflow that allows unauthenticated remote attackers to send specially crafted packets to an affected daemon process, achieving code execution with elevated privileges.

    “Multiple vulnerabilities exist in a daemon of ArubaOS-CX that may allow for improper processing of malformed input,” reads HPE’s bulletin.

    “An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service.”

    Affected release branches and fixes listed in the bulletin are:

    • 10.18.0001 → upgrade to 10.18.1002+
    • 10.17.1021 and earlier → 10.17.1030+
    • 10.16.1051 and earlier → 10.16.1060+
    • 10.13.1180 and earlier → 10.13.1190+
    • 10.10.1180 and earlier → 10.10.1181+

    HPE noted that the AOS-CX 10.10.1181 version has reached End of Maintenance (EOM) and only receives fixes for internally discovered, critical issues, a condition that also applies to CVE-2026-73749.

    ArubaOS-CX is HPE Aruba Networking’s operating system for its enterprise-grade network switches, typically used by large businesses, government agencies, universities, healthcare organizations, data centers, and service providers.

    HPE’s security bulletin also covers a set of 23 other security vulnerabilities, some with high severity ratings, between 8.1 and 8.8:

    • CVE-2026-73750: A low-privileged authenticated remote attacker can send malformed or truncated input to an AOS-CX management module, potentially causing denial of service or executing code with elevated privileges.
    • CVE-2026-73751: A low-privileged authenticated user can submit crafted input through the AOS-CX web-based management interface to execute arbitrary commands on the underlying operating system.
    • CVE-2026-73752: An unauthenticated attacker with adjacent-network access can exploit an AOS-CX API endpoint to write arbitrary files to the underlying operating system, potentially leading to remote code execution.
    • CVE-2026-73753: A low-privileged authenticated user can exploit affected AOS-CX command-line operations to execute arbitrary commands as a privileged user on the underlying operating system.
    • CVE-2026-73782: An unauthenticated attacker with adjacent-network access can exploit a format-string vulnerability in the AOS-CX command-line interface to execute arbitrary code as a privileged user on the underlying operating system.
    • CVE-2026-73781: An authenticated remote attacker can exploit a stored cross-site scripting vulnerability in the AOS-CX web-based management interface to execute arbitrary scripts in an administrator’s browser if the administrator interacts with the affected content.
    • CVE-2026-73780: An unauthenticated remote attacker can exploit missing CSRF protections in some certificate-authenticated AOS-CX sessions to submit arbitrary input to the web-based management interface by convincing an authenticated user to open a crafted URL.
    • CVE-2026-73779: An unauthenticated attacker with adjacent-network access can bypass authentication controls on AOS-CX switches, potentially exposing sensitive information, enabling unauthorized modifications, and disrupting services.
    • CVE-2026-73778: An unauthenticated remote attacker can use a predictable factory-default password to obtain full administrative control of an AOS-CX device that remains in its factory-default or post-ZTP state before an administrator configures credentials.
    • CVE-2026-73777: An unauthenticated remote attacker can exploit vulnerabilities in an AOS-CX API endpoint to bypass access controls and escalate privileges.

    The vendor “strongly encourages” customers to upgrade to one of the fixed releases listed in the bulletin.

    HPE mentions that, at the time of the bulletin’s publication, it was not aware of active exploitation or publicly available proof-of-concept exploits targeting the listed flaws.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    ArubaOSCX Code critical Execution Flaw HPE Patches remote
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal

    Microsoft: KB5120998 mouse reset bug affects only non-English PCs

    OpenAI confirms ChatGPT is down ahead of ‘Astra’ model launch

    HiddenLayer Raises $100 Million for AI Runtime Security

    US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries

    Microsoft says KB5120998 Windows update resets desktop settings

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Congressman says TikTok backed out of a meeting to avoid child safety questions

    September 3, 2026

    NVIDIA to acquire Hugging Face for $12.93B

    September 3, 2026

    HPE patches critical ArubaOS-CX remote code execution flaw

    September 3, 2026

    Wallet Recovery Experts Crack $1B ETH Wallet… But Find Just $10

    September 3, 2026
    Latest Posts

    Ultrafast X-rays capture chemistry unfolding atom by atom

    July 31, 2026

    How a PPE company’s highly publicized $32M Bitcoin strategy quietly expired without purchasing a single coin

    July 31, 2026

    Critical Flaw Led to Azure Cosmos DB Pwnage

    July 31, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Congressman says TikTok backed out of a meeting to avoid child safety questions

    September 3, 2026

    NVIDIA to acquire Hugging Face for $12.93B

    September 3, 2026

    HPE patches critical ArubaOS-CX remote code execution flaw

    September 3, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.