ArubaOS-CX CVE-2026-73749: Unauthenticated RCE via Input Processing Flaw in Daemon
1. Basic Information Article Title : HPE patches critical ArubaOS-CX remote code execution flaw Publisher : BleepingComputer Publication Date : 2026-09-03 Source : BleepingComputer Related Sources : HPE Aruba Networking security bulletin , HPE Advisory HPESBNW05134 (Official Text Version) , HPE Advisory HPESBNW05134 (CSAF) Related Malware / Threat Groups / CVEs / Products : CVE-2026-73749,…
HPE has addressed a critical remote code execution vulnerability in ArubaOS-CX. This flaw allows an unauthenticated attacker to execute arbitrary code with high privileges on the switch by sending specially crafted packets to the daemon. The vulnerability affects multiple versions of ArubaOS-CX. To mitigate the risk, it is recommended to update to the latest fixed version and implement temporary workarounds such as restricting CLI and web management access, logging user operations, and monitoring abnormal traffic.
Successful exploitation could enable the attacker to tamper with network settings, eavesdrop, or use the switch as a foothold for further compromise.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.