HPE addresses 23 critical vulnerabilities in AOS-CX software that could let hackers take over systems remotely.
Hewlett Packard Enterprise has released urgent software updates to address a collection of serious security weaknesses found in its AOS-CX network operating system. The company identified nearly two dozen separate problems, all grouped under the identifier CVE-2026-73749, with a severity rating of 9.8 out of 10. In security circles, this rating means the issue is nearly as dangerous as it gets.
These vulnerabilities are classified as remote code execution flaws. To understand what that means in simple terms: imagine your network switch is a locked building. Normally, only authorized people with proper credentials can enter. These security holes are like finding unlocked back doors that anyone on the internet could potentially push open and walk through. Once inside, an attacker could run commands, steal data, or cause serious damage.
The AOS-CX platform is a critical component in many large organizations' network infrastructure. It manages how data moves between different parts of a company's systems. When multiple serious vulnerabilities exist in such important equipment, it creates widespread risk.
What makes this situation particularly urgent is the combination of factors:
Think of your network infrastructure like the roads in a city. If someone gains control of the traffic lights and road signs, they can redirect all traffic wherever they want, monitor where everyone is going, or cause complete chaos.
If you work in IT administration: Your organization likely depends on network equipment like this to function. An uncorrected vulnerability could expose your entire company to serious breaches.
If you're a business decision maker: Network security incidents can cost millions of dollars in downtime, data recovery, and reputation damage. Prompt patching is far cheaper than dealing with a breach.
If you're just a regular employee: Even if you don't manage networks directly, a compromised network infrastructure could mean your personal work data, email, and files become accessible to criminals.
The fact that HPE released patches quickly shows the company is taking this seriously, but the window of time between when vulnerabilities are known and when all systems are patched remains dangerous.
If you manage HPE AOS-CX equipment in your organization:
If you work in a company but don't manage networks directly, consider reaching out to your IT department to confirm they're aware of and addressing this issue.
Patching network infrastructure quickly after critical vulnerabilities are disclosed remains one of the most important security practices any organization can follow.
Want to understand the technology behind this story? ITVedas has beginner-friendly guides on every IT topic.
Explore IT Chapters โ