CVE-2026-73750 – AOS-CX
“Multiple attack paths put network infrastructure, privileged access, and system integrity at risk.”
HPE patched multiple AOS-CX vulnerabilities covering unauthenticated and authenticated remote code execution, command injection, arbitrary file writes, authentication bypass, privilege escalation, stored XSS, CSRF, and unauthorized administrative access. CVE-2026-73749 has a CVSS score of 9.8, Critical severity. CVE-2026-73750, CVE-2026-73751, CVE-2026-73752, CVE-2026-73753, and CVE-2026-73782 each have a CVSS score of 8.8, High severity. CVE-2026-73781 is 8.4, CVE-2026-73780 is 8.3, CVE-2026-73779 is 8.2, and CVE-2026-73778 and CVE-2026-73777 are 8.1; all are High severity.
The updates are available in AOS-CX 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, and applicable 10.10.1181 releases. The 10.10 branch is end-of-maintenance and does not receive the full set of fixes.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- None
- CWE Classification
- CWE-284