HPE Patches Critical ArubaOS-CX Buffer Overflow (CVE-2026-73749) Enabling Unauthenticated Remote Code Execution
HPE Patches Critical ArubaOS-CX Buffer Overflow (TL-2026-2314) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-09-03 and last reviewed 2026-09-06. It has no confirmed attribution, affects Hewlett Packard Enterprise (Aruba Networking) ArubaOS-CX, references 11 CVEs (CVE-2026-73749, CVE-2026-73750, CVE-2026-73751), maps to 15 MITRE ATT&CK techniques (T1021, T1040, T1046), and is covered by 9 detection rules and 27 indicators of compromise.
Key facts for TL-2026-2314
- Threat ID
- TL-2026-2314
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- 2026-09-03
- Last reviewed
- 2026-09-06
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, education, health, finance, enterprise
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 27
- Updates
- 2026-09-06 · revalidated 1× · latest source
HPE disclosed and patched CVE-2026-73749 (CVSS 9.8), a critical buffer overflow in a daemon of ArubaOS-CX that lets an unauthenticated remote attacker send specially crafted packets to trigger memory corruption and achieve remote code execution with elevated privileges on Aruba CX-series switches. The flaw was released alongside a batch of related AOS-CX vulnerabilities (CVE-2026-73750 through CVE-2026-73782, CVSS 8.1-8.8) in HPE advisory hpesbnw05134en_us on September 1, 2026; HPE reported no known public proof-of-concept or active exploitation at disclosure.
How HPE Patches Critical ArubaOS-CX Buffer Overflow works
On September 1, 2026, Hewlett Packard Enterprise (HPE) Networking published security advisory hpesbnw05134en_us disclosing CVE-2026-73749, a critical (CVSS v3.1 9.8, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) buffer-overflow vulnerability affecting a daemon within ArubaOS-CX, the operating system used on HPE Aruba Networking's CX-series campus and data-center switches. According to the advisory description, multiple vulnerabilities exist in the affected daemon that allow improper processing of malformed input; an unauthenticated remote attacker can send specially crafted packets to the affected service to corrupt memory and achieve remote code execution with elevated privileges. Because the flaw requires no authentication, no privileges, and no user interaction (PR:N/UI:N) and is reachable over the network (AV:N), it presents an unauthenticated, pre-auth remote takeover path against core network switching infrastructure. HPE has not disclosed which specific daemon or network port is affected; no HPE advisory, NVD record, or independent research write-up reviewed identifies the process name, listening port, or protocol beyond the general description of 'specially crafted packets' sent to 'the affected service.'
The vulnerability spans five parallel AOS-CX release branches: 10.18.0001 and earlier, 10.17.1021 and earlier, 10.16.1051 and earlier, 10.13.1180 and earlier, and 10.10.1180 and earlier. HPE shipped fixed builds for each branch (10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, and 10.10.1181 respectively).
The same advisory batch discloses additional AOS-CX vulnerabilities in the CVE-2026-73750 to CVE-2026-73782 range, each independently confirmed with its own CVSS vector, CWE, and attack requirements: CVE-2026-73750 (CVSS 8.8, AV:N/AC:L/PR:L/UI:N) — malformed/truncated input processed by the authentication module, exploitable by an authenticated attacker relaying crafted data from a compromised or hostile authentication server, causing DoS or elevated-privilege RCE, CWE-284; CVE-2026-73751 (CVSS 8.8, AV:N/AC:L/PR:L/UI:N) — a low-privileged authenticated user submitting crafted input through the web-based management interface to execute arbitrary OS commands; CVE-2026-73752 (CVSS 8.8, AV:A/AC:L/PR:N/UI:N) — an unauthenticated, adjacent-network attacker exploiting a path-traversal flaw (CWE-22) in an API endpoint to write arbitrary files to the underlying OS, enabling RCE; CVE-2026-73753 (CVSS 8.8) — an authenticated low-privileged user abusing command-line operations to execute arbitrary commands as a privileged user; CVE-2026-73778 (CVSS 8.1) — the Credential Manager component shipping a predictable factory-default/post-ZTP password, letting an unauthenticated remote attacker gain full administrative access to a device that has not yet been configured by an administrator; CVE-2026-73779 (CVSS 8.2, adjacent/remote unauthenticated) — an authentication-bypass flaw in the AOS-CX operating system letting an unauthenticated remote actor circumvent existing authentication controls; and CVE-2026-73782 (CVSS 8.8, AV:A/AC:L/PR:N/UI:N) — a format-string vulnerability in the CLI reachable by an adjacent-network unauthenticated attacker, enabling arbitrary code execution as a privileged user. At the time of disclosure HPE stated it was not aware of any public discussion, proof-of-concept code, or exploitation of CVE-2026-73749 in the wild, and the CVE does not appear in the CISA Known Exploited Vulnerabilities catalog as of September 3, 2026.
This September 2026 batch (CVE-2026-73749/7375x/7378x) is a separate, later HPE Aruba Networking AOS-CX disclosure from the March 2026 CVE-2026-23813 through CVE-2026-23817 authentication-bypass/command-injection batch (advisory ~March 5-10, 2026, tracked separately by CSA Singapore AL-2026-023, SecurityAffairs, and Field Effect); the two batches affect overlapping AOS-CX version lines but are independent vulnerability sets and are not conflated here.
ArubaOS-CX switches are widely deployed as enterprise campus and data-center switching infrastructure across government agencies, universities, healthcare providers, and financial and data-center environments, making unpatched exposure of switch management/control-plane services to untrusted networks a high-value target for an attacker seeking a foothold or pivot point deep inside a target's network segmentation.
MITRE ATT&CK techniques used in TL-2026-2314
Lateral Movement
T1021 Remote Services; T1210 Exploitation of Remote Services
Collection
T1040 Network Sniffing; T1557 Adversary-in-the-Middle
Discovery
T1046 Network Service Discovery
Execution
T1059 Command and Scripting Interpreter; T1059.004 Command and Scripting Interpreter
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Persistence
T1078 Valid Accounts; T1078.001 Valid Accounts
Initial Access
T1190 Exploit Public-Facing Application
Impact
T1499 Endpoint Denial of Service
Credential Access
T1556 Modify Authentication Process
Reconnaissance
Affected products and versions in HPE Patches Critical ArubaOS-CX Buffer Overflow
- Hewlett Packard Enterprise (Aruba Networking) — ArubaOS-CX
Vulnerable versions: 10.18.0001 and earlier; 10.17.1021 and earlier; 10.16.1051 and earlier; 10.13.1180 and earlier; 10.10.1180 and earlier
Fixed in: 10.18.1002; 10.17.1030; 10.16.1060; 10.13.1190; 10.10.1181
Remediation for HPE Patches Critical ArubaOS-CX Buffer Overflow
Patches
- AOS-CX 10.18.1002
- AOS-CX 10.17.1030
- AOS-CX 10.16.1060
- AOS-CX 10.13.1190
- AOS-CX 10.10.1181
Immediate actions
- Apply the fixed ArubaOS-CX build for your branch: 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, or 10.10.1181
- Inventory all Aruba CX-series switches and confirm running firmware against the vulnerable ranges in HPE advisory hpesbnw05134en_us
- Restrict network reachability to switch management/control-plane services (web interface, API endpoints, CLI/SSH services) to trusted management networks only, pending patch deployment
- Rotate any factory-default or post-ZTP credentials on devices not yet fully configured, to close the CVE-2026-73778 exposure window
Workarounds
- No vendor-published workaround exists; HPE advisory hpesbnw05134en_us directs administrators to upgrade to a fixed AOS-CX release
Longer-term hardening
- Segment out-of-band management and control-plane traffic from general user/data-plane traffic to reduce exposure of switch daemons to untrusted networks
- Establish a recurring firmware patch-management cadence for network infrastructure devices, tracked separately from server/endpoint patching
- Deploy network monitoring capable of flagging anomalous or malformed packets directed at switch management interfaces
- Enforce a zero-touch-provisioning workflow that forces credential rotation before a device is reachable from any untrusted segment
CVEs associated with HPE Patches Critical ArubaOS-CX Buffer Overflow
CVE-2026-73749, CVE-2026-73750, CVE-2026-73751, CVE-2026-73752, CVE-2026-73753, CVE-2026-73777, CVE-2026-73778, CVE-2026-73779, CVE-2026-73780, CVE-2026-73781, CVE-2026-73782
Weaknesses (CWE) in HPE Patches Critical ArubaOS-CX Buffer Overflow
CWE-284, CWE-120
Timeline of HPE Patches Critical ArubaOS-CX Buffer Overflow
- CVE-2026-73749 reserved in the CVE program ahead of coordinated disclosure.
- HPE states it is not aware of any public discussion, proof-of-concept code, or active exploitation of CVE-2026-73749 at the time of disclosure.
- Third-party CVE trackers (OffSEQ Radar, cve.threatint.com) index and publish per-CVE technical breakdowns for CVE-2026-73750, -73751, -73752, -73753, -73778, and -73779, each independently confirming CVSS vector, CWE, and authentication prerequisites.
- CVE-2026-73749 published in the NVD with a CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- HPE publishes security advisory hpesbnw05134en_us disclosing CVE-2026-73749 and a batch of related ArubaOS-CX vulnerabilities (CVE-2026-73750 through CVE-2026-73782), with fixed firmware builds released for all five affected branches.
- CISA SSVC v2.0.3 assessment conducted on the advisory's CVEs: exploitation assessed as none, technical impact total.
- TheHackerWire publishes a technical write-up on CVE-2026-73782, the adjacent-network unauthenticated format-string RCE in the ArubaOS-CX CLI disclosed in the same advisory batch.
- BleepingComputer publishes coverage of the patched ArubaOS-CX flaw, summarizing affected/fixed versions and the unauthenticated RCE impact.
- NVD record for CVE-2026-73749 last modified, refreshing metadata after publication.
- NVD record for CVE-2026-73749 last-modified again; Tenable entry updated; still no public PoC or active exploitation, and the CVE remains absent from CISA KEV.
- SecurityWeek analysis highlights two independent unauthenticated RCE paths in the same bulletin: the daemon buffer overflow (CVE-2026-73749) and a CLI format-string bug (CVE-2026-73782) in different code components.
- Ongoing monitoring: no exploitation reports have surfaced since publication; EPSS score remains low (0.00532), but network-reachable RCE on switching infrastructure continues to warrant priority patching.
Update history for TL-2026-2314
- 2026-09-06 — CVE-2026-73749 — Critical Unauthenticated Buffer Overflow RCE in HPE ArubaOS-CX (HPESBNW05134): What changed No field escalation — severity remains CRITICAL, exploitability remains THEORETICAL, no known PoC or active exploitation. However, the scope of the underlying HPE advisory (hpesbnw05134en_us / HPESBNW05134) is now known to be f
Sources cited for HPE Patches Critical ArubaOS-CX Buffer Overflow
- HPE patches critical ArubaOS-CX remote code execution flaw
- HPE Support Advisory hpesbnw05134en_us
- NVD - CVE-2026-73749 Detail
- CVE-2026-73749: Unauth RCE in HPE Networking AOS-CX Scores 9.8
- CVE-2026-73749: Vulnerability in Hewlett Packard Enterprise (HPE) AOS-CX
- CVE-2026-73749
- CVE-2026-73750: Vulnerability in Hewlett Packard Enterprise (HPE) AOS-CX
- CVE-2026-73752: Vulnerability in Hewlett Packard Enterprise (HPE) AOS-CX
- CVE-2026-73778: Vulnerability in Hewlett Packard Enterprise (HPE) AOS-CX
- AOS-CX CLI Unauthenticated RCE (CVE-2026-73782)
More in vulnerability
- VLC Media Player: Integer Overflow in AllocatePicture (CVE-2026-56711) and RTSP Heap Out-of-Bounds Read (CVE-2026-73324)
- Dutch NCSC Warns of Critical Check Point VPN Flaws (CVE-2026-85102, CVE-2026-85103) — Exploitation Expected Imminently
- GitLab Patches Max-Severity Unauthenticated Path Traversal Flaw in Repository Commits API (CVE-2026-85706, CVSS 10.0)
- CVE-2026-0310: PAN-OS XML Processing Out-of-Bounds Write Enables Unauthenticated Root RCE
- Endor Labs Discloses 14 Critical/High Vulnerabilities Across Seven AI Orchestration Platforms (NocoBase, Flowise, Langflow, Dify, Activepieces, Kestra, Apache Airflow)
Detection coverage for TL-2026-2314
As of 2026-09-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2314 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.