Researchers have discovered 6 high-risk security vulnerabilities in HPE Aruba Networking AOS-CX (CVE-2026-73749 through CVE-2026-73753 and CVE-2026-73782). The vulnerability types include Improper Access Control, Command Injection, Path Traversal,
OS Command Injection, and Use of Externally-Controlled Format String. The most severe vulnerability allows an unauthenticated remote attacker to execute arbitrary code with elevated privileges by sending crafted packets to the affected service. Please verify and apply the patch as soon as possible.