← Back to news

HPE Patches Critical RCE Vulnerabilities in AOS-CX

SecurityWeek04/09/2026, 16:11
Read full article →

Summary

AI-Generated

Key Points:

  • HPE has released patches for 34 CVEs in the ArubaOS-CX platform, addressing critical remote code execution (RCE) vulnerabilities, particularly CVE-2026-73749 with a CVSS score of 9.8.
  • The vulnerabilities allow unauthenticated attackers to exploit the system by sending crafted packets, potentially leading to RCE with elevated privileges. Other issues could result in denial-of-service (DoS), privilege escalation, and information disclosure.
  • It is recommended to restrict CLI and web-based management interfaces to a dedicated VLAN and implement firewall policies for enhanced security.

Technical Details: The critical RCE vulnerabilities stem from improper processing of malformed input sent to a service within HPE's database-centric operating system for enterprise switches.

MITRE ATT&CK Techniques:

  • None mentioned

IOCs Mentioned:

  • None mentioned

Join the discussion — sign up to comment, upvote, and save articles.

Discussion

or to comment
Loading...

Loading comments...

Join 5,000+ security professionals

Get access to curated threat intel, upvote articles, join discussions, and build your karma in the SOC community.