


Perceptive Security
SOC/SIEM Consultancy

Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit…
Published:
1 September 2026 at 00:00:00
Alert date:
2 September 2026 at 00:16:07
Source:
nvd.nist.gov
Network Infrastructure, Zero-Day Vulnerabilities
Multiple vulnerabilities have been identified in a daemon component of HPE's AOS-CX network operating system. The flaws stem from improper processing of malformed input, allowing unauthenticated remote attackers to exploit them by sending specially crafted packets. Successful exploitation can result in remote code execution with elevated privileges. No authentication is required, making this particularly dangerous for exposed network devices. The vulnerabilities affect HPE AOS-CX, which runs on Aruba/HPE switching hardware. An official advisory has been published by HPE via their support portal. Organizations running AOS-CX should apply patches or mitigations as soon as they become available. The severity is high due to the unauthenticated RCE potential with privilege escalation.
Technical details
Mitigation steps:
Affected products:
HPE AOS-CX
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-73749
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
