Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-76658: HPE Fabric Composer lets attackers take full control

CVE-2026-76658 · published 2 days ago
Summary

The SSH service in HPE Networking Fabric Composer can be accessed without a password, allowing an outside attacker to log in as an administrator. Once inside, the attacker can run any command on the server, effectively taking over the system. Apply the latest security update from HPE or disable SSH access until it is patched.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
hewlett packard enterprise (hpe) fabric composer <= 7.3.3
arubanetworks fabric_composer <= 7.3.3
cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
Original advisory text
A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Su...
A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system leading to complete system compromise.
Severity
10.0 Critical
CVSS 3.1: 10.0 (MITRE)
Exploitation
EPSS <1%
Type
CWE-287Improper Authentication
Timeline
Published1 Sep 2026
Updated2 Sep 2026
First seen1 Sep 2026
Sources
CVE-2026-76658 · MITRE
Monitor software like this
Free during beta