HPE Patches Critical RCE Vulnerabilities in AOS-CX
BLUF
HPE urgently patched critical RCE flaws in AOS-CX affecting network infrastructure.
NEWS
Security Week reports that HPE addressed nearly two dozen security issues in AOS-CX, collectively tracked under CVE-2026-73749 with a maximum CVSS score of 9.8. These updates resolve remote code execution vulnerabilities that could allow attackers to take control of affected devices without authentication.
Why I Care
With a CVSS score of 9.8, these flaws pose an immediate threat to network integrity, potentially allowing unauthenticated attackers to execute arbitrary code on critical infrastructure devices used by enterprises and service providers.
Next Steps
Network administrators should immediately apply the latest HPE AOS-CX patches to all affected switches and routers, verify patch installation, and monitor logs for signs of exploitation prior to patching.
Source: Security Week ·