Hewlett Packard Enterprise has released a patch for a critical buffer overflow (CVE‑2026‑73749) in ArubaOS‑CX that could allow unauthenticated remote code execution. All affected branches must be upgraded immediately.

  • Critical buffer overflow (CVE‑2026‑73749) patched.
  • All affected ArubaOS‑CX branches require immediate upgrade.
  • Bulletin lists 23 additional high‑severity flaws.

Hewlett Packard Enterprise (HPE) today patched a critical remote code execution flaw in its ArubaOS‑CX network operating system. The vulnerability, tracked as CVE‑2026‑73749, is a buffer overflow that lets unauthenticated attackers send specially crafted packets to a daemon, gaining elevated‑privilege code execution.

Affected Releases and Fixes

The security bulletin specifies the following upgrade paths:

  • 10.18.0001 → 10.18.1002+
  • 10.17.1021 and earlier → 10.17.1030+
  • 10.16.1051 and earlier → 10.16.1060+
  • 10.13.1180 and earlier → 10.13.1190+
  • 10.10.1180 and earlier → 10.10.1181+ (EOM status)

Historical Background

ArubaOS‑CX has faced several security incidents over the past years, notably two major RCE bugs in 2022‑2024 that forced large enterprises to accelerate their patch cycles. Those events highlighted the platform’s central role in critical infrastructure and the need for rigorous vulnerability management.

Why This Matters

BozokMedia analysis shows that ArubaOS‑CX powers switches in hospitals, data centers, and government agencies; a successful exploit could disrupt essential services and expose sensitive data.

“This patch not only closes CVE‑2026‑73749 but also shines a light on 23 other vulnerabilities that demand immediate remediation.”
Did You Know?: The 2019 version of ArubaOS‑CX suffered a similar buffer overflow that impacted over 5,000 switches worldwide.

Frequently Asked Questions

Q1: Do devices need to be rebooted after applying the patch?
A: Reboots are not mandatory for most updates, but a restart ensures all components run the new code.

Q2: Has the flaw been actively exploited in the wild?
A: HPE stated that, at the time of publication, no public proof‑of‑concept or active exploitation was known.