Junglewise Threat Intelligence

CVE-2026-73774: HPE AOS-CX buffer overflow in underlying operating system

CVE-2026-73774 · Severity: high · CVSS 7.6 · Published 2026-09-01

Vendors: Hpe.

Executive brief

AOS-CX is HPE's network operating system used in enterprise switches and routers to manage network traffic and security. A buffer overflow flaw in the underlying OS allows an attacker to send malicious network packets that could leak sensitive configuration or operational data and potentially disrupt network connectivity and services.

Technical details

A buffer overflow vulnerability exists in the underlying operating system code of AOS-CX that can be triggered by sending specially crafted network packets to an affected device. The vulnerability requires no authentication and is reachable over the network, making it remotely exploitable. Successful exploitation could result in information disclosure (limited read of memory contents) or limited information modification, as well as potential denial of service through system disruption. A patch from HPE is likely available; users should check the HPE support portal for fixes specific to their AOS-CX version.

Affected products

  • HPE AOS-CX

Timeline

  • 2026-09-01: disclosed

References