HPE Aruba patches two unauthenticated code-execution flaws in AOS-CX
On September 1, 2026, advisory HPESBNW05134 fixes more than twenty vulnerabilities in ArubaOS-CX, including two independent bugs — CVE-2026-73749 (CVSS 9.8) and CVE-2026-73782 — that each give unauthenticated code execution on a switch. Isolate the management plane and apply the fixed branch before a public exploit turns these flaws into a mass campaign.