Summary
| Parameter | Value |
|---|---|
| CVE ID | CVE-2026-76657 |
| Alert Source | GitHub Advisory - Critical Vulnerability |
| CVE Publication Year | 2026 |
| Date Published | 2026-09-01 |
| Vendor | HPE |
| Product | Networking Fabric Composer |
| CVSS Score | 10.0 (critical) |
| EPSS Score | No data |
| CISA KEV | No |
| Ransomware | Not confirmed |
Vulnerability Description
HPE published a bulletin covering five vulnerabilities in Networking Fabric Composer (AFC) - the controller managing Aruba CX network fabrics. This entry consolidates them, as they share one product and one update.
| CVE | CVSS | Nature of the flaw |
|---|---|---|
| CVE-2026-76657 | 10.0 | Authentication bypass in the AFC API. An unauthenticated remote attacker gains administrative privileges and full control of the host. |
| CVE-2026-76658 | 10.0 | Flaw in the SSH daemon. An unauthenticated remote attacker gains administrative access and executes arbitrary commands as a privileged OS user. |
| CVE-2026-19766 | 9.6 | Authentication bypass in the underlying operating system. An unauthenticated adjacent attacker executes arbitrary code as a privileged user. |
| CVE-2026-73701 | 9.0 | Unauthenticated remote code execution in the underlying OS, exploitable when preconditions outside the attacker’s control are met. |
| CVE-2026-73700 | 9.0 | Stored XSS in the web management interface. An authenticated low-privilege operator can attack an administrative user. |
Fabric Composer sits in the network management plane, not on a single application server. Compromising AFC means control over the configuration of the entire switch fabric - the ability to change segmentation, redirect traffic, or persist in network infrastructure below the visibility of most EDR tooling.
Required Actions
- Update HPE Networking Fabric Composer to the version named in the HPE security bulletin. A single update addresses all five flaws - there is no case for patching them individually.
- Remove the AFC API and management interface from general-purpose networks. A fabric controller belongs on a dedicated out-of-band management network, not on a user VLAN.
- Restrict SSH access to the AFC host by source address. CVE-2026-76658 is exploitable without authentication, so network-level filtering is the only effective compensating control before patching.
- Review operator accounts. CVE-2026-73700 requires a low-privilege account - audit the AFC user list and remove unused and shared accounts.
- Compare the current fabric configuration against an approved baseline. Unauthorised VLAN, ACL or route changes are the most likely evidence of exploitation.
- Review AFC host authentication logs for successful administrative logins originating outside the management network.
Who Is Affected?
Organisations using HPE Networking Fabric Composer (formerly Aruba Fabric Composer) to manage Aruba CX switch fabrics - typically in data centres.
This mainly affects large enterprises and institutions that built their data centre on HPE/Aruba hardware: banks, telecommunications operators, energy utilities and larger manufacturing plants. Fabric Composer appears wherever the DC network is managed centrally rather than switch by switch.
AFC instances reachable only from an out-of-band network are less exposed, but patching remains necessary - CVE-2026-19766 requires only adjacent-network access.
Sources
Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.
