Security1 distinct publisher2 min readPublished
CVE-2026-73749 lets an unauthenticated attacker run privileged code on HPE Aruba switches by sending malformed packets to a daemon the bulletin never names. The oldest affected branch is already out of maintenance.
The Watch · Security desk
build
A UDP packet is now enough: IKEEXT RCE moves from patch queue to fire drill1 distinct publisher
build
TerminalFix delivers its first stage through the clipboard of the person it targets1 distinct publisher
product
Quantinuum brings in Quanta, and concedes the bottleneck is packaging, not qubit count1 distinct publisher
security
ShinyHunters dumps 12.9 million Carhartt records after a refused $3.3 million ransom1 distinct publisher
Compiled by The WatchSomething wrong?How this is made
HPE's bulletin does not name the affected daemon or the port it listens on [20]. That removes the usual stopgap. With no service to match, there is no control-plane ACL to stage while a change board argues about a reload on a core switch, and the fixed build is the only control the vendor puts forward [15]. Containment falls back to who can reach the management plane at all, which is the same assumption three of the other flaws in the same bulletin attack from an adjacent network [10][9][11].
The bulletin totals 24 CVEs: one critical plus 23 others [17]. HPE described eleven of them in prose, and seven of those eleven require no credentials [18]. Three of the seven need adjacent-network access, which leaves four reachable by a remote unauthenticated caller: the overflow itself, the API access-control bypass in CVE-2026-73777, the missing CSRF protections in CVE-2026-73780, and the predictable factory-default password in CVE-2026-73778 [19][12][14][8].
CVE-2026-73778 needs no exploit code at all. Per HPE it applies to a switch sitting in factory-default or post-ZTP state, before an administrator configures credentials, and it yields full administrative control [8]. That is an inventory question rather than a research question: how many boxes were racked, provisioned by ZTP, and never had a password set. At the other end, CVE-2026-73781 is less pressing. The stored cross-site scripting requires an authenticated attacker and an administrator who interacts with the content [13].
The 10.10 branch is the clearest case of the pattern. HPE's listed fix for 10.10.1180 and earlier is 10.10.1181 [4], and 10.10.1181 is the build HPE says has reached End of Maintenance, receiving fixes only for internally discovered critical issues [5]. The remediation build and the terminal build are the same build [21]. This CVE qualified under that condition [5]. The next one qualifies only if HPE finds it internally and rates it critical. Note the other end of the list too: 10.18.0001, the newest branch named, is affected as well [4]. Moving to a newer branch alone will not fix this; only the specific builds do.
Ranked by verification strength, evidence, and original report placement.
CVE-2026-73749 is a buffer overflow in a daemon of ArubaOS-CX that allows unauthenticated remote attackers to send specially crafted packets to the affected service and achieve code execution with elevated privileges.
Hewlett Packard Enterprise has patched a critical remote code execution vulnerability in the ArubaOS-CX network operating system.
HPE's bulletin states: "Multiple vulnerabilities exist in a daemon of ArubaOS-CX that may allow for improper processing of malformed input" and that "An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service."
Affected release branches and fixes listed in the bulletin: 10.18.0001 to 10.18.1002+; 10.17.1021 and earlier to 10.17.1030+; 10.16.1051 and earlier to 10.16.1060+; 10.13.1180 and earlier to 10.13.1190+; 10.10.1180 and earlier to 10.10.1181+.
HPE noted that AOS-CX 10.10.1181 has reached End of Maintenance and only receives fixes for internally discovered, critical issues, a condition that also applies to CVE-2026-73749.
ArubaOS-CX is HPE Aruba Networking's operating system for its enterprise-grade network switches, typically used by large businesses, government agencies, universities, healthcare organizations, data centers, and service providers.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 3, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Vendor-authoritative, singly sourced, deliberately vague on the critical flaw
HPE describing bugs in HPE's own operating system is about as authoritative as vulnerability reporting gets, and BleepingComputer quotes the bulletin rather than paraphrasing it. The ceiling comes from what the bulletin withholds: the daemon behind the critical remote code execution path is unnamed, no port or protocol is given, no CVSS vector accompanies the critical label, and thirteen of the 24 CVEs are never described. Nobody outside HPE has checked any of it.
Fixes shipped everywhere; uptake and exposure entirely unmeasured
The remediation side is fully populated — every listed branch has a build to move to, and HPE is pushing customers toward them. The field side is empty. Nothing tells us how many AOS-CX switches are deployed, how many expose the affected service, or how many have upgraded, and the enterprise, government, healthcare and service-provider install base is asserted as a category rather than counted. On the 10.10 branch, patching lands you on a build that is already out of maintenance.
Restrained framing, slightly under-weighted aggregate
Nothing here is inflated: the headline tracks HPE's own severity call, and BleepingComputer prints the no-exploitation, no-public-proof-of-concept line without hedging it into a threat. If anything the single-CVE framing undersells the pile. Seven of eleven described flaws need no login, a predictable factory-default password hands over full administrative control of an unconfigured device, and the oldest affected branch has already left maintenance — read together, that is a management-plane story larger than one buffer overflow.
Vendor sets the disclosure boundary; the page carries a sponsored placement
Two pressures worth naming, neither disqualifying. HPE controls how much detail leaves the building, and withholding the daemon name and port is defensible practice that also happens to make independent scrutiny impossible while pointing every reader toward an upgrade. And the coverage itself ends with a promotional pitch for a commercial security report, adjacent to advisory copy — normal for the outlet, but it is a paid interest sharing the page with the analysis.
Solid on what was said, thin on what it means operationally
Confidence is high that the bulletin says what the reporting says it says — the quotes, the build numbers and the CVE inventory are all reproducible from one document. It drops from there. Severity rests on HPE's unexplained critical label, exploitability cannot be reasoned about without the component or its listening port, and the exploitation status is a vendor snapshot dated to publication that no one has refreshed.