HPE Patches Critical RCE Vulnerabilities in AOS-CX
HPE has released patches to address 34 critical vulnerabilities in its ArubaOS-CX platform, a database-centric operating system for enterprise switches. These flaws, including a high-severity RCE vulnerability, could allow unauthenticated attackers to execute code with elevated privileges, highlighting a significant risk for organizations relying on HPE’s networking equipment.
Hewlett Packard Enterprise (HPE) has released patches to address 34 critical vulnerabilities in its ArubaOS-CX platform, a database-centric operating system for enterprise switches. These flaws, including a high-severity remote code execution (RCE) vulnerability, could allow unauthenticated attackers to execute code with elevated privileges, highlighting a significant risk for organizations relying on HPE’s networking equipment. The vulnerabilities were discovered internally by HPE’s security team and are being addressed in versions 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, and 10.10.1181.
Many of these bugs are tracked together under single CVEs, with CVE-2026-73749 being a particularly high-severity issue with a CVSS score of 9.8. The critical security defects are rooted in the improper processing of malformed input sent to an unnamed service within HPE’s database-centric operating system. An unauthenticated attacker could exploit these defects by sending crafted packets to the vulnerable service, achieving RCE with elevated privileges.
In addition to the high-severity RCE vulnerability, 22 other high-severity CVEs were addressed, potentially leading to denial-of-service (DoS), RCE, arbitrary command execution, arbitrary script code execution in a victim’s browser, authentication bypass, privilege escalation, and information disclosure. The remaining 11 CVEs are medium-severity flaws leading to access controls bypass, information disclosure, arbitrary file reads, DoS, and privilege escalation.
HPE recommends restricting the CLI and web-based management interfaces to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above, along with accounting controls for tracking and logging user activities and resource usage, to minimize the risk of exploitation. The company states that it is not aware of any of these vulnerabilities being exploited in the wild at the time of this release.