LIVE · cybersecurity feed
Live wire
Introducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak modelsHPE patches critical ArubaOS-CX remote code execution flawCVE-2026-82329 · Attackers Pounce on Critical Artifactory Flaw Following DisclosureCVE-2026-0768 · Critical Langflow flaw exploited to steal OpenAI and AWS keysCVE-2026-82329 · Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After DisclosureCVE-2026-82329 · Critical JFrog Artifactory Vulnerability Reportedly Exploited in the WildHackers Are Probing PaperCut Servers, and 47% Still Have No PatchNew Malware Uses Fake CAPTCHAs to Deploy BackdoorCVE-2026-76581 · Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCECVE-2026-76639 · Hack One Robot, Reach the Next: Unitree G1 Security Flaws
vulnerabilitycritical

HPE patches critical ArubaOS-CX remote code execution flaw

Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution. [...]

zeroday.news ·

Hewlett Packard Enterprise (HPE) has released patches for a critical remote code execution vulnerability, identified as CVE-2026-73749, affecting its ArubaOS-CX network operating system. This buffer overflow flaw allows unauthenticated attackers to achieve elevated privileges and execute code by sending specially crafted packets to a vulnerable daemon process.

ArubaOS-CX is the operating system for HPE Aruba Networking's enterprise-grade network switches, which are widely deployed in large businesses, government agencies, universities, healthcare organizations, data centers, and by service providers.

HPE's security bulletin details that the vulnerability stems from improper processing of malformed input within a daemon of ArubaOS-CX. The company urges customers to upgrade to patched versions immediately. Affected release branches and their corresponding fixes include: 10.18.0001 should upgrade to 10.18.1002+ 10.17.1021 and earlier should upgrade to 10.17.1030+ 10.16.1051 and earlier should upgrade to 10.16.1060+ 10.13.1180 and earlier should upgrade to 10.13.1190+ 10.10.1180 and earlier should upgrade to 10.10.1181+

HPE notes that version 10.10.1181 of AOS-CX has reached its End of Maintenance (EOM) phase, meaning it will only receive fixes for critical issues discovered internally, a category that includes CVE-2026-73749.

In addition to the critical CVE-2026-73749, HPE's bulletin addresses 23 other security vulnerabilities in ArubaOS-CX, several of which carry high severity ratings between 8.1 and 8.8. These include:

CVE-2026-73750: An authenticated remote attacker with low privileges can cause a denial of service or execute code with elevated privileges by sending malformed or truncated input to an AOS-CX management module.

CVE-2026-73751: A low-privileged authenticated user can execute arbitrary commands on the underlying operating system by submitting crafted input through the AOS-CX web-based management interface.

CVE-2026-73752: An unauthenticated attacker with adjacent-network access can exploit an AOS-CX API endpoint to write arbitrary files to the underlying operating system, potentially leading to remote code execution.

CVE-2026-73753: A low-privileged authenticated user can execute arbitrary commands as a privileged user on the underlying operating system by exploiting affected AOS-CX command-line operations.

CVE-2026-73782: An unauthenticated attacker with adjacent-network access can exploit a format-string vulnerability in the AOS-CX command-line interface to execute arbitrary code as a privileged user on the underlying operating system.

CVE-2026-73781: An authenticated remote attacker can exploit a stored cross-site scripting vulnerability in the AOS-CX web-based management interface to execute arbitrary scripts in an administrator’s browser if the administrator interacts with the affected content.

CVE-2026-73780: An unauthenticated remote attacker can exploit missing Cross-Site Request Forgery (CSRF) protections in some certificate-authenticated AOS-CX sessions to submit arbitrary input to the web-based management interface by convincing an authenticated user to open a crafted URL.

CVE-2026-73779: An unauthenticated attacker with adjacent-network access can bypass authentication controls on AOS-CX switches, potentially exposing sensitive information, enabling unauthorized modifications, and disrupting services.

CVE-2026-73778: An unauthenticated remote attacker can obtain full administrative control of an AOS-CX device by using a predictable factory-default password if the device remains in its factory-default or post-Zero Touch Provisioning (ZTP) state before an administrator configures credentials.

CVE-2026-73777: An unauthenticated remote attacker can exploit vulnerabilities in an AOS-CX API endpoint to bypass access controls and escalate privileges.

HPE confirmed that as of the bulletin's publication date, it had no knowledge of active exploitation or publicly available proof-of-concept exploits for any of the listed vulnerabilities.

vulnerabilitypatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilitycritical

Introducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak models

Use production traffic and security signals to prioritize findings, prepare edge mitigations when safe, and propose code patches. By combining WAF data with OpenAI Daybreak models, Vulnerability Discovery and Remediation helps teams identify and patch the most critical threats first.

ai

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

ai

[Virtual Event] Building a Secure AI Strategy for the Enterprise

finance

Large Enterprises Targeted in Fake Merger & Acquisition Scams

Threat actors behind the "Phantom Deal" campaign are studying companies in extreme detail, aiming to dupe midlevel employees into initiating large financial transfers.

security

Pegasus and NoviSpy Used Against Serbian Protesters

Serbian activists were targeted with zero-click Pegasus and NoviSpy spyware, exposing a major surveillance campaign ahead of elections. A member of Serbia’s student protest movement had their iPhone infected with NSO Group‘s Pegasus spyware without ever clicking a link or opening a file. The Citizen Lab confirmed the infection in collaboration with the SHARE Foundation, […]

security

Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC

A shared security 'Nightmare'