CVE-2026-73749 is an unauthenticated remote-code-execution issue in ArubaOS-CX, HPE Aruba Networking’s operating system for CX enterprise switches. The software runs the network infrastructure beneath campus and data-centre connectivity: access switches, aggregation and core systems, and top-of-rack deployments. That puts it in the hands of organisations operating sizeable managed networks, including businesses, government agencies, universities, healthcare providers, data centres and service providers.
The problem is notable because an attacker need not log in first. HPE assigns a 9.8 CVSS score and says a remote attacker can send specially crafted packets to an affected service; if exploitation succeeds, they can execute code with elevated privileges. In practical terms, a device that should be forwarding and controlling network traffic may instead run attacker-supplied actions. The attacker does need network reachability to the exposed service, but no credentials or user interaction.
The packet path remains unnamed
HPE describes multiple flaws in an unnamed daemon that improperly processes malformed input. That is enough to establish the attack class, but not enough to identify the listening port, protocol, daemon name, source file or the precise bounds-checking failure. There is no public vendor patch diff or verified vulnerable-code pattern to inspect, so teams should not assume that restricting one familiar management protocol addresses the issue.
The vendor advisory lists Aruba CX 10000, 4100i, 6000, 6100, 6200F, 6300, 6400, 8320, 8325, 8360, 8400 and 9300 series as affected hardware families. AOS-CX’s modular, programmable design includes APIs and automation capabilities, but it is still the switch OS itself—not an optional application—that is at stake. Its role across enterprise campus and data-centre switching means a successful compromise could give an intruder a privileged foothold at a consequential network control point.
Upgrade, then narrow management exposure
Fixed releases are AOS-CX 10.18.1002 and later, 10.17.1030 and later, 10.16.1060 and later, 10.13.1190 and later, and 10.10.1181 and later. The affected lines include 10.18.0001; 10.17.1021 and below; 10.16.1051 and below; 10.13.1180 and below; and 10.10.1180 and below. Prioritise an upgrade to the applicable fixed release, validate the image and reboot plan against switch redundancy and maintenance requirements, then confirm the running version rather than treating a downloaded image as remediation.
The 10.10 branch is End of Maintenance, and HPE says its fix coverage is limited to internally identified critical-severity issues. Other End-of-Maintenance versions should be presumed affected unless specifically excluded; End-of-Support installations were not assessed and should likewise be treated as potentially affected. While upgrades are scheduled, put CLI and web-management access on a dedicated Layer 2 segment or VLAN, or restrict it with Layer 3 firewall policy, and retain accounting and logging. Those controls reduce reachable attack surface; they do not replace the update.
No public exploitation signal so far
As of September 4, 2026, HPE was not aware of active exploitation, and no incident or campaign had been publicly tied to CVE-2026-73749. It is not in CISA’s KEV catalogue, which is not proof that exploitation has never occurred. No public proof of concept has surfaced in the sources checked as of that date.
Treat this as an urgent inventory-and-upgrade task, especially where switch management services cross trust boundaries. SecAlerts monitors an organisation’s actual software stack and alerts on new vulnerabilities affecting the products it runs, helping teams find this kind of exposure before a bulletin becomes an incident.




