HPE patches 34 flaws in Aruba network switches

Published

HPE has published fixes for 34 separate vulnerabilities in Aruba networking products, and Hong Kong's CERT has picked the release up as a medium-risk bulletin for defenders. The affected software is AOS-CX, the operating system that runs on Aruba switches, so this is patching work for the network team rather than the desktop fleet.

The identifiers arrive in one almost unbroken block, CVE-2026-73749 through CVE-2026-73783, with a single number absent from the middle of the run. A contiguous block like that is what a coordinated internal review looks like when it reaches disclosure, rather than 34 findings turning up from 34 directions.

Which switches need the update

The bulletin lists the affected builds as AOS-CX 10.18.0001, plus 10.17.1021, 10.16.1051, 10.13.1180 and 10.10.1180 and below on their respective branches. The 10.10 branch carries an end-of-maintenance marker, and that is the line worth reading twice. If you are still running it, check the vendor advisory for whether a fixed build exists for that branch at all before you start planning a change window around one.

Six kinds of damage, and no map between them

Between them, the bulletin says, the flaws allow remote code execution, security restriction bypass, denial of service, cross-site scripting, information disclosure and elevation of privilege, and can be reached by a remote attacker. That is the full extent of what has been made public here. There is no CVSS score for any of the 34, no mapping of which identifier produces which effect, no affected-configuration detail, and no statement that any of them has been exploited. We are not going to fill those gaps by guesswork, and nor should anyone else. HPE's own advisory is where the per-issue detail lives and it is the original source; the CERT bulletin is a restatement of it.

Patch it on the normal schedule

Nothing published so far argues for an emergency change window. Nothing published argues for ignoring it either, because remote code execution sits at the top of that impact list and a switch operating system is not a place where that is ever routine. Read the HPE advisory, confirm which of your branches is affected, and schedule the upgrade the way you would any other switch firmware change.

This is the third enterprise networking rollup in a week. Cisco disclosed a pair of open ports that hand root on Nexus 9000 switches and seven flaws affecting every IOS XR release within days of each other. Network operating systems now draw the same steady stream of vulnerability disclosures as everything else, and they sit on the boxes with the longest patch intervals in the building.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions