Hewlett Packard Enterprise has patched a critical vulnerability in ArubaOS-CX, the network operating system used by HPE Aruba Networking enterprise switches, according to BleepingComputer. The flaw is tracked as CVE-2026-73749 and could allow remote code execution against affected systems. BleepingComputer, citing HPE’s bulletin, reports that the issue is a buffer overflow in a daemon process. HPE described the problem as improper processing of malformed input in ArubaOS-CX and said an unauthenticated remote attacker could exploit it by sending specially crafted packets to the affected service. The important operational detail is privilege. BleepingComputer reports that successful exploitation could result in code execution with elevated privileges, which makes the flaw more serious than a denial-of-service-only bug in network infrastructure. ArubaOS-CX runs on enterprise-grade switches used by large businesses, government agencies, universities, healthcare organizations, data centers, and service providers, BleepingComputer notes. That installed-base profile makes patch timing material for infrastructure teams, even though the provided reporting does not identify any known victims. HPE’s bulletin also covered 23 other vulnerabilities, according to BleepingComputer. Some of those were rated high severity, with scores between 8.1 and 8.8, and HPE “strongly encourages” customers to move to fixed releases listed in the bulletin. One caveat: HPE said that, at the time the bulletin was published, it was not aware of active exploitation or public proof-of-concept exploit code targeting the listed flaws, according to BleepingComputer. That makes this a patch-priority story rather than, based on the provided material, an incident-response story. HPE also noted that AOS-CX 10.10.1181 has reached End of Maintenance. BleepingComputer reports that this release receives fixes only for internally discovered critical issues, a condition HPE said also applied to CVE-2026-73749. Who benefits: Organizations that can quickly identify ArubaOS-CX exposure and apply HPE’s fixed releases reduce risk before public exploit code appears. Network and security teams benefit from treating the advisory as infrastructure maintenance, not just endpoint patching. Who's exposed: Enterprises, public-sector organizations, universities, healthcare providers, data centers, and service providers running affected ArubaOS-CX versions are the exposed population described in the reporting. Systems still on AOS-CX 10.10.1181 require extra attention because that release is already End of Maintenance.