Critical CVE-2026-73749 Remote Code Execution Vulnerability in HPE ArubaOS-CX: Affected Versions, Risks, and Patch Guidance

HPE has issued a critical security update to address a remote code execution vulnerability (CVE-2026-73749) in its ArubaOS-CX network operating system. The flaw, which carries a CVSS score of 9.8, allows unauthenticated attackers to execute arbitrary code on enterprise-grade switches.
Why it matters
Given the widespread use of these switches in government and healthcare, this vulnerability poses a significant risk to critical infrastructure if not patched immediately.
min read ← All posts Critical CVE-2026-73749 Remote Code Execution Vulnerability in HPE ArubaOS-CX: Affected Versions, Risks, and Patch Guidance
Hewlett Packard Enterprise (HPE) has released critical security updates for its ArubaOS-CX (AOS-CX) network operating system, addressing multiple vulnerabilities, most notably the critical unauthenticated remote code execution ( RCE ) flaw tracked as CVE-2026-73749 . These vulnerabilities impact enterprise-grade network switches that are widely deployed across large organizations, government agencies, healthcare, and data centers. At the time of writing, there is no evidence of exploitation in the wild, no public proof-of-concept code, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in