Skip to content
Security Alerts

CVE-2026-73749: Unauthenticated RCE in HPE Aruba Networking AOS-CX

Multiple flaws in an AOS-CX daemon allow an unauthenticated remote attacker to execute code with elevated privileges by sending specially crafted packets...

Summary

ParameterValue
CVE IDCVE-2026-73749
Alert SourceGitHub Advisory - Critical Vulnerability
CVE Publication Year2026
Date Published2026-09-01
VendorHPE
ProductAruba Networking AOS-CX
CVSS Score9.8 (critical)
EPSS ScoreNo data
CISA KEVNo
RansomwareNot confirmed

Vulnerability Description

Multiple vulnerabilities exist in a daemon of the AOS-CX operating system running on HPE Aruba Networking CX switches, all rooted in improper processing of malformed input.

An unauthenticated remote attacker can exploit them by sending specially crafted packets to the affected service. The result is remote code execution with elevated privileges - directly on the switch, with no credentials required.

The CVSS 9.8 rating reflects the absence of preconditions: network reachability of the service is enough. A compromised switch gives an attacker a position from which to observe and redirect traffic, collapse VLAN segmentation, and maintain access independently of the security posture of servers and workstations.

Required Actions

  1. Update AOS-CX firmware to the release named in HPE’s security bulletin for your switch family (6000, 6100, 6200, 6300, 6400, 8000, 8100, 8320, 8325, 8360, 8400, 9300, 10000 - the bulletin lists affected models and releases).
  2. Restrict access to the switch management plane. Management interfaces and control services should be reachable only from a dedicated out-of-band network.
  3. Apply control-plane ACLs limiting traffic to switch system services to trusted addresses - the baseline compensating control ahead of a maintenance window.
  4. Verify switch configuration against an approved baseline; look for unauthorised changes to ACLs, VLANs, static routes and local accounts.
  5. Plan the upgrade as a maintenance window. Core switches require a reboot - in VSX environments, upgrade asymmetrically, node by node.
  6. Forward switch logs to your SIEM if you are not already collecting them. Without network-layer telemetry, exploitation of this vulnerability class is effectively undetectable.

Who Is Affected?

Organisations operating HPE Aruba Networking CX switches running AOS-CX - in the data centre and in campus access layers alike.

The installed base is broad: Aruba CX is the networking standard in many banks, telecommunications operators, energy utilities, public administration bodies and manufacturing companies that refreshed their networks in recent years.

Highest risk applies to switches whose system services are reachable from user or partner networks. Confirm the affected AOS-CX release range in HPE’s bulletin - not every firmware branch is in scope.

Sources


Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.

Learn More

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist