- Description
- A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system leading to complete system compromise.
- Source
- security-alert@hpe.com
- NVD status
- Analyzed
- Products
- fabric_composer
CVSS 3.1
- Type
- Secondary
- Base score
- 10
- Impact score
- 6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-287
- Hype score
- Not currently trending
HPE Fabric Composer の脆弱性 CVE-2026-76658 などが FIX:基盤となるホストの完全侵害の恐れ https://t.co/kVofurAGaF HPE Networking Fabric Composer の SSH デーモンや API
@iototsecnews
9 Sept 2026
92 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔑 HPE Networking Fabric Composer SSH daemon: unauthenticated RCE gives attackers full admin access. CVSS 10. No auth, no interaction, network-exploitable. CVE-2026-76658 #cybersecurity #ciso #cto #vulnerabilities #mssp https://t.co/prUofAqoyJ https://t.co/MLdnSO3luu
@SecAlertsCo
4 Sept 2026
108 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️ #ExploitGrid Daily #Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-75604 - EXPLOIT CVE-2026-63137 - EXPLOIT CVE-2026-76657 CVE-2026-76658 CVE-2026-84147 ..🧵👇
@exploitgrid
3 Sept 2026
47 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Multiple critical #Vulnerabilities have been discovered in #HPE Aruba Networking Fabric Composer. Upgrade immediately to remain safe. #CVE-2026-76657 #CVE-2026-76658 #CVE-2026-19766 #CVE-2026-73700 #CVE-2026-73701 https://t.co/ELqHt6CXYI
@NCIIPC
2 Sept 2026
562 Impressions
0 Retweets
2 Likes
0 Bookmarks
1 Reply
0 Quotes
Critical vulnerabilities in HPE Fabric Composer allow unauthenticated attackers to bypass authentication, execute arbitrary code, and gain full admin access. CVE-2026-76657 and CVE-2026-76658 score 10.0. Users must update versions and lock down APIs, SSH, and web interfaces ASAP
@dailytechonx
2 Sept 2026
56 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
HPE disclosed 52 vulnerabilities in Aruba Networking Fabric Composer, five rated Critical. CVE-2026-76657 and CVE-2026-76658 allow remote admin takeover via API and unauthenticated SSH command execution. CVE-2026-73701 enables unauthenticated RCE under certain conditions. Apply
@WorldCyberNewsX
2 Sept 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*",
"matchCriteriaId": "9D4FBA23-A05C-4C71-9AC4-67F7F68C7A35",
"versionEndIncluding": "7.3.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]