HPE Fixes Critical Flaws in AOS-CX Switch Software
HPE has released security updates addressing almost two dozen vulnerabilities in its AOS-CX network switch software, collectively tracked as CVE-2026-73749 and rated a maximum-severity 9.8 on the CVSS scale. Vulnerabilities of this severity typically allow an attacker to remotely execute code on a device without needing valid credentials, potentially giving them full control over the switch.
AOS-CX runs on HPE's networking hardware, which many organisations use to manage internal traffic and connect devices across their office or data centre. A compromised switch can act as a foothold for attackers to intercept traffic, move laterally through a network, or disrupt operations entirely, making these kinds of vulnerabilities especially serious for any business relying on HPE networking equipment.
HPE has already issued patches to resolve the flaws, and administrators managing AOS-CX devices should apply the updates as soon as possible. Given the critical severity score, organisations should treat this as a high-priority patching task rather than something to schedule for a future maintenance window.