HPE Patches Critical ArubaOS-CX Buffer Overflow (CVE-2026-73749) Enabling Unauthenticated Remote Code Execution

HPE Patches Critical ArubaOS-CX Buffer Overflow (TL-2026-2314) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-09-03 and last reviewed 2026-09-06. It has no confirmed attribution, affects Hewlett Packard Enterprise (Aruba Networking) ArubaOS-CX, references 11 CVEs (CVE-2026-73749, CVE-2026-73750, CVE-2026-73751), maps to 15 MITRE ATT&CK techniques (T1021, T1040, T1046), and is covered by 9 detection rules and 27 indicators of compromise.

Key facts for TL-2026-2314

Threat ID
TL-2026-2314
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
PATCHED
Category
VULNERABILITY
First published
2026-09-03
Last reviewed
2026-09-06
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, education, health, finance, enterprise
Target regions
Global
Detection rules
9
Indicators of compromise
27
Updates
2026-09-06 · revalidated 1× · latest source

HPE disclosed and patched CVE-2026-73749 (CVSS 9.8), a critical buffer overflow in a daemon of ArubaOS-CX that lets an unauthenticated remote attacker send specially crafted packets to trigger memory corruption and achieve remote code execution with elevated privileges on Aruba CX-series switches. The flaw was released alongside a batch of related AOS-CX vulnerabilities (CVE-2026-73750 through CVE-2026-73782, CVSS 8.1-8.8) in HPE advisory hpesbnw05134en_us on September 1, 2026; HPE reported no known public proof-of-concept or active exploitation at disclosure.

How HPE Patches Critical ArubaOS-CX Buffer Overflow works

On September 1, 2026, Hewlett Packard Enterprise (HPE) Networking published security advisory hpesbnw05134en_us disclosing CVE-2026-73749, a critical (CVSS v3.1 9.8, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) buffer-overflow vulnerability affecting a daemon within ArubaOS-CX, the operating system used on HPE Aruba Networking's CX-series campus and data-center switches. According to the advisory description, multiple vulnerabilities exist in the affected daemon that allow improper processing of malformed input; an unauthenticated remote attacker can send specially crafted packets to the affected service to corrupt memory and achieve remote code execution with elevated privileges. Because the flaw requires no authentication, no privileges, and no user interaction (PR:N/UI:N) and is reachable over the network (AV:N), it presents an unauthenticated, pre-auth remote takeover path against core network switching infrastructure. HPE has not disclosed which specific daemon or network port is affected; no HPE advisory, NVD record, or independent research write-up reviewed identifies the process name, listening port, or protocol beyond the general description of 'specially crafted packets' sent to 'the affected service.'

The vulnerability spans five parallel AOS-CX release branches: 10.18.0001 and earlier, 10.17.1021 and earlier, 10.16.1051 and earlier, 10.13.1180 and earlier, and 10.10.1180 and earlier. HPE shipped fixed builds for each branch (10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, and 10.10.1181 respectively).

The same advisory batch discloses additional AOS-CX vulnerabilities in the CVE-2026-73750 to CVE-2026-73782 range, each independently confirmed with its own CVSS vector, CWE, and attack requirements: CVE-2026-73750 (CVSS 8.8, AV:N/AC:L/PR:L/UI:N) — malformed/truncated input processed by the authentication module, exploitable by an authenticated attacker relaying crafted data from a compromised or hostile authentication server, causing DoS or elevated-privilege RCE, CWE-284; CVE-2026-73751 (CVSS 8.8, AV:N/AC:L/PR:L/UI:N) — a low-privileged authenticated user submitting crafted input through the web-based management interface to execute arbitrary OS commands; CVE-2026-73752 (CVSS 8.8, AV:A/AC:L/PR:N/UI:N) — an unauthenticated, adjacent-network attacker exploiting a path-traversal flaw (CWE-22) in an API endpoint to write arbitrary files to the underlying OS, enabling RCE; CVE-2026-73753 (CVSS 8.8) — an authenticated low-privileged user abusing command-line operations to execute arbitrary commands as a privileged user; CVE-2026-73778 (CVSS 8.1) — the Credential Manager component shipping a predictable factory-default/post-ZTP password, letting an unauthenticated remote attacker gain full administrative access to a device that has not yet been configured by an administrator; CVE-2026-73779 (CVSS 8.2, adjacent/remote unauthenticated) — an authentication-bypass flaw in the AOS-CX operating system letting an unauthenticated remote actor circumvent existing authentication controls; and CVE-2026-73782 (CVSS 8.8, AV:A/AC:L/PR:N/UI:N) — a format-string vulnerability in the CLI reachable by an adjacent-network unauthenticated attacker, enabling arbitrary code execution as a privileged user. At the time of disclosure HPE stated it was not aware of any public discussion, proof-of-concept code, or exploitation of CVE-2026-73749 in the wild, and the CVE does not appear in the CISA Known Exploited Vulnerabilities catalog as of September 3, 2026.

This September 2026 batch (CVE-2026-73749/7375x/7378x) is a separate, later HPE Aruba Networking AOS-CX disclosure from the March 2026 CVE-2026-23813 through CVE-2026-23817 authentication-bypass/command-injection batch (advisory ~March 5-10, 2026, tracked separately by CSA Singapore AL-2026-023, SecurityAffairs, and Field Effect); the two batches affect overlapping AOS-CX version lines but are independent vulnerability sets and are not conflated here.

ArubaOS-CX switches are widely deployed as enterprise campus and data-center switching infrastructure across government agencies, universities, healthcare providers, and financial and data-center environments, making unpatched exposure of switch management/control-plane services to untrusted networks a high-value target for an attacker seeking a foothold or pivot point deep inside a target's network segmentation.

MITRE ATT&CK techniques used in TL-2026-2314

Lateral Movement

T1021 Remote Services; T1210 Exploitation of Remote Services

Collection

T1040 Network Sniffing; T1557 Adversary-in-the-Middle

Discovery

T1046 Network Service Discovery

Execution

T1059 Command and Scripting Interpreter; T1059.004 Command and Scripting Interpreter

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Persistence

T1078 Valid Accounts; T1078.001 Valid Accounts

Initial Access

T1190 Exploit Public-Facing Application

Impact

T1499 Endpoint Denial of Service

Credential Access

T1556 Modify Authentication Process

Reconnaissance

T1592 Gather Victim Host Information; T1595 Active Scanning

Affected products and versions in HPE Patches Critical ArubaOS-CX Buffer Overflow

  • Hewlett Packard Enterprise (Aruba Networking) — ArubaOS-CX
    Vulnerable versions: 10.18.0001 and earlier; 10.17.1021 and earlier; 10.16.1051 and earlier; 10.13.1180 and earlier; 10.10.1180 and earlier
    Fixed in: 10.18.1002; 10.17.1030; 10.16.1060; 10.13.1190; 10.10.1181

Remediation for HPE Patches Critical ArubaOS-CX Buffer Overflow

Patches

  • AOS-CX 10.18.1002
  • AOS-CX 10.17.1030
  • AOS-CX 10.16.1060
  • AOS-CX 10.13.1190
  • AOS-CX 10.10.1181

Immediate actions

  • Apply the fixed ArubaOS-CX build for your branch: 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, or 10.10.1181
  • Inventory all Aruba CX-series switches and confirm running firmware against the vulnerable ranges in HPE advisory hpesbnw05134en_us
  • Restrict network reachability to switch management/control-plane services (web interface, API endpoints, CLI/SSH services) to trusted management networks only, pending patch deployment
  • Rotate any factory-default or post-ZTP credentials on devices not yet fully configured, to close the CVE-2026-73778 exposure window

Workarounds

  • No vendor-published workaround exists; HPE advisory hpesbnw05134en_us directs administrators to upgrade to a fixed AOS-CX release

Longer-term hardening

  • Segment out-of-band management and control-plane traffic from general user/data-plane traffic to reduce exposure of switch daemons to untrusted networks
  • Establish a recurring firmware patch-management cadence for network infrastructure devices, tracked separately from server/endpoint patching
  • Deploy network monitoring capable of flagging anomalous or malformed packets directed at switch management interfaces
  • Enforce a zero-touch-provisioning workflow that forces credential rotation before a device is reachable from any untrusted segment

CVEs associated with HPE Patches Critical ArubaOS-CX Buffer Overflow

CVE-2026-73749, CVE-2026-73750, CVE-2026-73751, CVE-2026-73752, CVE-2026-73753, CVE-2026-73777, CVE-2026-73778, CVE-2026-73779, CVE-2026-73780, CVE-2026-73781, CVE-2026-73782

Weaknesses (CWE) in HPE Patches Critical ArubaOS-CX Buffer Overflow

CWE-284, CWE-120

Timeline of HPE Patches Critical ArubaOS-CX Buffer Overflow

  • CVE-2026-73749 reserved in the CVE program ahead of coordinated disclosure.
  • HPE states it is not aware of any public discussion, proof-of-concept code, or active exploitation of CVE-2026-73749 at the time of disclosure.
  • Third-party CVE trackers (OffSEQ Radar, cve.threatint.com) index and publish per-CVE technical breakdowns for CVE-2026-73750, -73751, -73752, -73753, -73778, and -73779, each independently confirming CVSS vector, CWE, and authentication prerequisites.
  • CVE-2026-73749 published in the NVD with a CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
  • HPE publishes security advisory hpesbnw05134en_us disclosing CVE-2026-73749 and a batch of related ArubaOS-CX vulnerabilities (CVE-2026-73750 through CVE-2026-73782), with fixed firmware builds released for all five affected branches.
  • CISA SSVC v2.0.3 assessment conducted on the advisory's CVEs: exploitation assessed as none, technical impact total.
  • TheHackerWire publishes a technical write-up on CVE-2026-73782, the adjacent-network unauthenticated format-string RCE in the ArubaOS-CX CLI disclosed in the same advisory batch.
  • BleepingComputer publishes coverage of the patched ArubaOS-CX flaw, summarizing affected/fixed versions and the unauthenticated RCE impact.
  • NVD record for CVE-2026-73749 last modified, refreshing metadata after publication.
  • NVD record for CVE-2026-73749 last-modified again; Tenable entry updated; still no public PoC or active exploitation, and the CVE remains absent from CISA KEV.
  • SecurityWeek analysis highlights two independent unauthenticated RCE paths in the same bulletin: the daemon buffer overflow (CVE-2026-73749) and a CLI format-string bug (CVE-2026-73782) in different code components.
  • Ongoing monitoring: no exploitation reports have surfaced since publication; EPSS score remains low (0.00532), but network-reachable RCE on switching infrastructure continues to warrant priority patching.

Update history for TL-2026-2314

Sources cited for HPE Patches Critical ArubaOS-CX Buffer Overflow

More in vulnerability

Detection coverage for TL-2026-2314

As of 2026-09-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2314 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats