Get Your Free Report
Start for Free
SOCRadar® Cyber Intelligence Inc. | CVE-2026-73749: HPE ArubaOS-CX RCE
Sep 04, 2026
5 Mins Read
Moon
Summarize with:

CVE-2026-73749: HPE ArubaOS-CX RCE

HPE patched CVE-2026-73749, a critical unauthenticated Remote Code Execution (RCE) vulnerability in HPE Aruba Networking AOS-CX, also known as ArubaOS-CX.

The flaw affects an AOS-CX daemon and can be exploited through specially crafted network packets. Successful exploitation could allow RCE with elevated privileges on affected switches, making patching a priority for organizations that rely on ArubaOS-CX for campus, data center, or critical network connectivity.

What Is CVE-2026-73749?

CVE-2026-73749 (CVSS 9.8) covers multiple vulnerabilities in an AOS-CX daemon that improperly processes malformed input. According to HPE’s security bulletin, an unauthenticated remote attacker could exploit the issue by sending specially crafted packets to the affected service. Successful exploitation could result in remote code execution with elevated privileges.

Details of CVE-2026-73749 (SOCRadar Vulnerability Intelligence)

Details of CVE-2026-73749 (SOCRadar Vulnerability Intelligence)

Which AOS-CX Versions Are Affected?

HPE identifies the following affected AOS-CX branches and fixed releases:

AOS-CX branch Affected versions Fixed version
10.18 10.18.0001 10.18.1002 or later
10.17 10.17.1021 and earlier 10.17.1030 or later
10.16 10.16.1051 and earlier 10.16.1060 or later
10.13 10.13.1180 and earlier 10.13.1190 or later
10.10 10.10.1180 and earlier 10.10.1181 or later

Administrators should verify the exact running image, not only the major branch. HPE also noted that AOS-CX 10.10.1181 has reached End of Maintenance and receives fixes only for internally discovered critical issues, including CVE-2026-73749.

Devices beyond End of Support should be treated cautiously and moved to a supported release path where possible.

What Component Is Vulnerable?

The vulnerable component is an AOS-CX daemon that mishandles malformed input. HPE does not identify the daemon name, affected protocol, packet structure, vulnerable function, or patch-level code changes in the public advisory.

In plain language, a network-reachable service may process attacker-controlled packet data unsafely. If exploitation succeeds, an attacker could execute code with elevated privileges on the switch.

That matters because switches are high-value infrastructure assets. A compromised device could allow an attacker to alter configuration, disrupt traffic, modify routing or segmentation, weaken access controls, or collect sensitive network and device information. The exact follow-on impact depends on the device role and surrounding controls.

How Could CVE-2026-73749 Be Exploited?

The high-level attack path is straightforward:

  • An attacker reaches the affected AOS-CX service over the network.
  • The attacker sends malformed, specially crafted packets.
  • The daemon mishandles the input.
  • Successful exploitation may allow elevated remote code execution.

The CVSS vector indicates that exploitation requires no credentials and no user interaction. However, public material does not confirm which service, port, protocol, or deployment condition makes a device reachable. Defenders should therefore treat network exposure as a key risk factor without assuming that internal placement alone removes exposure.

Is There Active Exploitation?

HPE stated during the disclosure that it was unaware of any active exploitation. Furthermore, there is no confirmed in-the-wild exploitation as of September 4, 2026.

The absence of confirmed exploitation or public PoC code does not reduce the need to patch. Unauthenticated network reachability and elevated-privilege RCE can become urgent quickly if technical details emerge.

SOCRadar’s Vulnerability Intelligence

SOCRadar’s Vulnerability Intelligence

SOCRadar’s Cyber Threat Intelligence enables organizations to stay updated on vulnerabilities like CVE-2026-73749, official advisory announcements, exploitation developments, and public PoC releases.

Additionally, SOCRadar’s Attack Surface Management (ASM) helps identify exposed AOS-CX assets, public-facing services, vulnerable technologies, and reachable infrastructure. Combining threat intelligence with ASM allows security teams to effectively prioritize affected switches that require urgent patch validation and exposure mitigation.

What Should Defenders Do Right Now?

Patch and Verify

Upgrade affected devices to the applicable fixed release:

  • 10.18.1002 or later
  • 10.17.1030 or later
  • 10.16.1060 or later
  • 10.13.1190 or later
  • 10.10.1181 or later

Confirm the active image after the upgrade. Do not rely only on staged images, planned maintenance records, or centralized inventory that may be outdated.

Prioritize High-Risk Switches

Prioritize devices with management or control-plane services reachable from untrusted, user, guest, partner, or external networks. Also prioritize switches supporting critical segmentation, routing, data center connectivity, or high-availability paths.

Review End of Maintenance and End of Support deployments and plan migration to supported releases where needed.

Reduce Exposure if Patching Is Delayed

HPE does not provide a validated workaround for CVE-2026-73749 in the reviewed bulletin. If immediate patching is delayed, restrict switch management and control-plane access to dedicated management networks. Use management-plane ACLs, firewall rules, and segmentation to limit reachable source networks.

These controls reduce exposure, but they do not replace patching.

Hunt for Suspicious Activity

The HPE bulletin does not provide vendor-specific IoCs, packet signatures, port guidance, or a forensic procedure. Defenders should combine version-based exposure assessment with behavioral review.

Look for unexplained daemon crashes, service restarts, reboots, failovers, watchdog events, or control-plane instability. Review changes to VLANs, routing, ACLs, authentication, administrative accounts, logging, SNMP, management access, and firmware settings.

Correlate unusual packet activity, device instability, configuration changes, and administrative logins before patch deployment. Preserve switch logs, centralized management records, flow data, packet captures where available, and configuration snapshots.