Summary
| Parameter | Value |
|---|---|
| CVE ID | CVE-2026-73749 |
| Alert Source | GitHub Advisory - Critical Vulnerability |
| CVE Publication Year | 2026 |
| Date Published | 2026-09-01 |
| Vendor | HPE |
| Product | Aruba Networking AOS-CX |
| CVSS Score | 9.8 (critical) |
| EPSS Score | No data |
| CISA KEV | No |
| Ransomware | Not confirmed |
Vulnerability Description
Multiple vulnerabilities exist in a daemon of the AOS-CX operating system running on HPE Aruba Networking CX switches, all rooted in improper processing of malformed input.
An unauthenticated remote attacker can exploit them by sending specially crafted packets to the affected service. The result is remote code execution with elevated privileges - directly on the switch, with no credentials required.
The CVSS 9.8 rating reflects the absence of preconditions: network reachability of the service is enough. A compromised switch gives an attacker a position from which to observe and redirect traffic, collapse VLAN segmentation, and maintain access independently of the security posture of servers and workstations.
Required Actions
- Update AOS-CX firmware to the release named in HPE’s security bulletin for your switch family (6000, 6100, 6200, 6300, 6400, 8000, 8100, 8320, 8325, 8360, 8400, 9300, 10000 - the bulletin lists affected models and releases).
- Restrict access to the switch management plane. Management interfaces and control services should be reachable only from a dedicated out-of-band network.
- Apply control-plane ACLs limiting traffic to switch system services to trusted addresses - the baseline compensating control ahead of a maintenance window.
- Verify switch configuration against an approved baseline; look for unauthorised changes to ACLs, VLANs, static routes and local accounts.
- Plan the upgrade as a maintenance window. Core switches require a reboot - in VSX environments, upgrade asymmetrically, node by node.
- Forward switch logs to your SIEM if you are not already collecting them. Without network-layer telemetry, exploitation of this vulnerability class is effectively undetectable.
Who Is Affected?
Organisations operating HPE Aruba Networking CX switches running AOS-CX - in the data centre and in campus access layers alike.
The installed base is broad: Aruba CX is the networking standard in many banks, telecommunications operators, energy utilities, public administration bodies and manufacturing companies that refreshed their networks in recent years.
Highest risk applies to switches whose system services are reachable from user or partner networks. Confirm the affected AOS-CX release range in HPE’s bulletin - not every firmware branch is in scope.
Sources
Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.
