Network Security

HPE patches ArubaOS-CX switches vulnerable to remote code execution

Aruba, a Hewlett Packard Enterprise company sign atop headquarters building. Aruba Networks is a wireless networking subsidiary of HPE

Hewlett Packard Enterprise (HPE) on Sept. 1 released patches for 35 flaws in its ArubaOS-CX switches, the top one being a critical buffer overflow that could result in a remote code execution with elevated privileges if exploited.

While there’s no sign of exploitation just yet, security pros said teams should apply the patches, especially for critical CVSS 9.8 CVE-2026-73749.

“There’s currently no indication that the vulnerability is being actively exploited, but we shouldn’t interpret that as a comfortable window to wait,” said Matan Shavit, GM for North America at Hadrian. “Once a critical vulnerability affecting widely deployed enterprise infrastructure is disclosed, defenders have to assume that researchers and attackers alike will work to understand how they can exploit it. Teams need to reduce that window of exposure before somebody succeeds.”

Shane Barney, chief information security officer at Keeper Security added that network operating systems control segmentation, traffic flow and access to critical infrastructure. Barney said admin access to AOS-CX switches means lateral movement across network segments, traffic interception, and redirection to sensitive systems.

“From there, attackers can modify access control policies and reach identity infrastructure directly,” said Barney. “This is a direct path to control over the network. Organizations should assume this is already being exploited. While patching is mandatory and should be completed immediately, it's not the full answer. Network device credentials demand the same governance and visibility as any other privileged access: secure storage, regular rotation and real-time audit of every administrative action.”

Ram Varadarajan, founder and CEO at Acalvio, said network administrators fear this type of bug the most: an attacker might need no password or user interaction — only the ability to reach an affected device — to potentially take control of it.

“Given what we've been seeing recently, we can expect that AI agents will increasingly automate attacks using mechanisms such as these,” said Varadarajan. “Future defenses are going to need model-aware cyberdeception that can recognize and manipulate an attacker’s machine-driven decision-making, not merely block malicious traffic.”

Roman Sannikov, global research coordinator at iCounter, agreed that no active exploitation doesn't mean no interest yet: bugs like this usually get reverse-engineered from the patch diff within days, and network switches are a softer target than people think.

“Security teams push emergency patches to internet-facing servers fast, but switching infrastructure often sits on a slower change-management cycle, because taking a switch down means an outage, unlike restarting a single service,” explained Sannikov. “That gap between a patch being available and a patch actually applied to the switch fabric is the exact window an initial access broker is watching for.”

An In-Depth Guide to Network Security

Get essential knowledge and practical strategies to fortify your network security.
Steve Zurier
Steve Zurier has been a freelance writer and editor for SC Media since 2012. Now, Zurier writes daily news stories and edits SC Media’s Perspectives columns. A long-time member of the tech press, Zurier lives in Columbia, MD. During off-hours, Steve moonlights as an upright bassist for jazz and klezmer bands around the Baltimore/DC area.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds