CVE-2026-73782 – AOS-CX

CVSS 8.8 IMPORTANT Critical - Same Day Deployment

“Multiple attack paths put network infrastructure, privileged access, and system integrity at risk.”

HPE patched multiple AOS-CX vulnerabilities covering unauthenticated and authenticated remote code execution, command injection, arbitrary file writes, authentication bypass, privilege escalation, stored XSS, CSRF, and unauthorized administrative access. CVE-2026-73749 has a CVSS score of 9.8, Critical severity. CVE-2026-73750, CVE-2026-73751, CVE-2026-73752, CVE-2026-73753, and CVE-2026-73782 each have a CVSS score of 8.8, High severity. CVE-2026-73781 is 8.4, CVE-2026-73780 is 8.3, CVE-2026-73779 is 8.2, and CVE-2026-73778 and CVE-2026-73777 are 8.1; all are High severity.

The updates are available in AOS-CX 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, and applicable 10.10.1181 releases. The 10.10 branch is end-of-maintenance and does not receive the full set of fixes.

Key Details

Affected Product
Hpe Arubaos-cx
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-134
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.