About:
CVE-2026-73749 is a critical remote code execution vulnerability affecting HPE Aruba Networking AOS-CX switches. The flaw stems from multiple buffer overflow vulnerabilities that can be exploited remotely without authentication, allowing attackers to execute code with elevated privileges on affected devices. Organizations should prioritize upgrading vulnerable AOS-CX deployments or implement vendor-recommended network segmentation controls until updates can be applied.
RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.
Identifier: CVE-2026-73749
PoC or Exploitation: No known exploitation at this time.
CVSS Score: 9.8 (Critical, CVSS v3.1)
Update / Patch:
HPE Networking has released fixed versions addressing this vulnerability. A workaround is also available.
Affected versions include:
Fixed versions include:
The End of Maintenance 10.10.x branch received fixes only for internally identified Critical-severity vulnerabilities.
Affected hardware includes:
Aruba CX 4100i, 6000, 6100, 6200F, 6300, 6400, 8320, 8325, 8360, 8400, 9300, and 10000 Switch Series.
HPE Security Bulletin HPESBNW05134:
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US
Description:
CVE-2026-73749 covers multiple buffer overflow vulnerabilities in a daemon of AOS-CX, the operating system running on HPE Aruba Networking switches.
An unauthenticated remote attacker can exploit these vulnerabilities by sending specially crafted packets to the affected service. Successful exploitation can result in remote code execution with elevated privileges. No authentication or user interaction is required.
Mitigation Recommendation:
Upgrade to the applicable fixed AOS-CX version for your platform as soon as possible.
If immediate patching is not possible, apply the vendor's workaround: restrict CLI and web-based management interfaces to a dedicated Layer 2 segment or VLAN, and enforce Layer 3 and above firewall policies.
Enable accounting controls to track and log user activity and resource usage on affected devices.