Affected Systems

ArubaOS-CX network operating system on HPE Aruba enterprise switches. Affected versions: 10.18.0001, 10.17.1021 and earlier, 10.16.1051 and earlier, 10.13.1180 and earlier, 10.10.1180 and earlier. Used in large enterprises, government, healthcare, data centers, and service providers.

Exploitation Status

No active exploitation or public proof-of-concept known at time of vendor disclosure. HPE states they are not aware of exploitation targeting CVE-2026-73749 or the 23 additional vulnerabilities patched in the same bulletin.

Business Impact

CVE-2026-73749 is a buffer overflow allowing unauthenticated remote attackers to execute arbitrary code with elevated privileges by sending crafted packets to an affected daemon. This represents full system compromise of critical network infrastructure. Additional high-severity flaws (CVSS 8.1-8.8) include authenticated RCE, adjacent-network RCE, authentication bypass, and privilege escalation. Exploitation could enable lateral movement, traffic interception, network disruption, and persistent access to enterprise networks.

Urgency

🟠 Within 24 hours

Recommended Actions

  • Immediately inventory all HPE Aruba switches running ArubaOS-CX and identify affected versions using 'show version' command
  • Upgrade ArubaOS-CX to patched versions: 10.18.1002+, 10.17.1030+, 10.16.1060+, 10.13.1190+, or 10.10.1181+ depending on current branch
  • Review network segmentation to ensure management interfaces for ArubaOS-CX switches are not exposed to untrusted networks or the internet
  • Monitor switch logs and SIEM for unusual daemon crashes, unexpected authentication attempts, or anomalous API calls to ArubaOS-CX management services
  • Verify no switches remain in factory-default or post-ZTP state with default credentials (addresses CVE-2026-73778)