Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-73749: AOS-CX service can let attackers run code remotely
CVE-2026-73749 · published 2 days ago
Summary
A part of the AOS-CX system that handles network traffic can be confused by specially crafted data. An attacker who does not need to log in could send these data packets and cause the system to run their own code with high-level permissions. Apply the latest software updates or patches from the vendor as soon as possible to close this gap.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| hewlett packard enterprise (hpe) | aos-cx | <= 10.18.0001 |
Original advisory text
Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending spe...
Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service. Successful exploitation could result in remote code execution with elevated privileges.
Severity
9.8
Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-284Improper Access Control
Timeline
Published1 Sep 2026
Updated2 Sep 2026
First seen2 Sep 2026
Monitor software like this
Free during beta