Hewlett Packard Enterprise has released updates for its Aruba Networking AOS-CX switch operating system covering 34 CVEs, led by a group of roughly two dozen issues tracked together as CVE-2026-73749 and rated 9.8 out of 10.
HPE’s advisory traces the critical cluster to how the database-centric OS handles malformed input routed to an unnamed service. Crafted packets sent to the exposed service let an unauthenticated attacker run code remotely with elevated rights.
Beyond the cluster sit 22 high-severity fixes, touching denial of service, RCE, arbitrary command execution, browser script execution, authentication bypass, privilege escalation and information disclosure, along with 11 medium-severity items covering access-control bypass, arbitrary file reads and the like. Across AOS-CX versions 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190 and 10.10.1181, more than 150 flaws get fixes.
HPE reports most issues surfaced through internal discovery and says it has seen no evidence of exploitation. It still recommends restricting CLI and web-based management interfaces to a dedicated layer-2 segment or VLAN protected by firewall policies, a routine that matters more as switch CVEs tend to be weaponized quickly once disclosed.
