Jump to the main content block

【Vulnerability Alert】HPE Aruba Networking AOS-CX Contains Six High-Risk Security Vulnerabilities. Please Confirm and Apply Patches as Soon as Possible

publish date : 2026-09-30 update date : 2026-10-02

Source: Ministry of education information & communication security contingency platform

"" "" ""

Publication Number TACERT-ANA-2026091808091414 Publication Time 2026-09-18 08:50:15
Incident Type ANA-Vulnerability Alert Discovery Time 2026-09-18 08:50:15
Impact Level Medium  
[Subject]
【Vulnerability Alert】HPE Aruba Networking AOS-CX Contains Six High-Risk Security Vulnerabilities. Please Confirm and Apply Patches as Soon as Possible
[Content]

Forwarded from the National Institute of Cyber Security Cybersecurity Alert NISAC-200-202609-00000014

Researchers discovered six high-risk security vulnerabilities in HPE Aruba Networking AOS-CX (CVE-2026-73749 through CVE-2026-73753 and CVE-2026-73782), including Improper Access Control, Command Injection, Path Traversal, OS Command Injection, and Use of Externally-Controlled Format String vulnerabilities. The most severe vulnerability may allow an unauthenticated remote attacker to send specially crafted packets to an affected service and execute arbitrary code with elevated privileges. Please confirm and apply patches as soon as possible.

Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed)

[Affected Platform]

AOS-CX version 10.18.0001A
OS-CX version 10.17.1021 and earlier
AOS-CX version 10.16.1051 and earlier
AOS-CX version 10.13.1180 and earlier
AOS-CX version 10.10.1180 and earlier

[Recommended Actions]

The official vendor has released patches or updates for the vulnerabilities. Please refer to the official instructions for remediation. The URL is as follows:

https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US

[Reference]

1. https://nvd.nist.gov/vuln/detail/CVE-2026-73749
2. https://nvd.nist.gov/vuln/detail/CVE-2026-73750
3. https://nvd.nist.gov/vuln/detail/CVE-2026-73751
4. https://nvd.nist.gov/vuln/detail/CVE-2026-73752
5. https://nvd.nist.gov/vuln/detail/CVE-2026-73753
6. https://nvd.nist.gov/vuln/detail/CVE-2026-73782
7. https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US

(This notification is for informational purposes only and does not constitute a cybersecurity incident).
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw
Organizer: Computer Center
Click Num: