Skip to content
Security Alerts

CVE-2026-76657: Five Critical Flaws in HPE Networking Fabric Composer

HPE published a bulletin covering five flaws in Networking Fabric Composer, including two rated CVSS 10.0 that let an unauthenticated attacker fully compromise the AFC host...

Summary

ParameterValue
CVE IDCVE-2026-76657
Alert SourceGitHub Advisory - Critical Vulnerability
CVE Publication Year2026
Date Published2026-09-01
VendorHPE
ProductNetworking Fabric Composer
CVSS Score10.0 (critical)
EPSS ScoreNo data
CISA KEVNo
RansomwareNot confirmed

Vulnerability Description

HPE published a bulletin covering five vulnerabilities in Networking Fabric Composer (AFC) - the controller managing Aruba CX network fabrics. This entry consolidates them, as they share one product and one update.

CVECVSSNature of the flaw
CVE-2026-7665710.0Authentication bypass in the AFC API. An unauthenticated remote attacker gains administrative privileges and full control of the host.
CVE-2026-7665810.0Flaw in the SSH daemon. An unauthenticated remote attacker gains administrative access and executes arbitrary commands as a privileged OS user.
CVE-2026-197669.6Authentication bypass in the underlying operating system. An unauthenticated adjacent attacker executes arbitrary code as a privileged user.
CVE-2026-737019.0Unauthenticated remote code execution in the underlying OS, exploitable when preconditions outside the attacker’s control are met.
CVE-2026-737009.0Stored XSS in the web management interface. An authenticated low-privilege operator can attack an administrative user.

Fabric Composer sits in the network management plane, not on a single application server. Compromising AFC means control over the configuration of the entire switch fabric - the ability to change segmentation, redirect traffic, or persist in network infrastructure below the visibility of most EDR tooling.

Required Actions

  1. Update HPE Networking Fabric Composer to the version named in the HPE security bulletin. A single update addresses all five flaws - there is no case for patching them individually.
  2. Remove the AFC API and management interface from general-purpose networks. A fabric controller belongs on a dedicated out-of-band management network, not on a user VLAN.
  3. Restrict SSH access to the AFC host by source address. CVE-2026-76658 is exploitable without authentication, so network-level filtering is the only effective compensating control before patching.
  4. Review operator accounts. CVE-2026-73700 requires a low-privilege account - audit the AFC user list and remove unused and shared accounts.
  5. Compare the current fabric configuration against an approved baseline. Unauthorised VLAN, ACL or route changes are the most likely evidence of exploitation.
  6. Review AFC host authentication logs for successful administrative logins originating outside the management network.

Who Is Affected?

Organisations using HPE Networking Fabric Composer (formerly Aruba Fabric Composer) to manage Aruba CX switch fabrics - typically in data centres.

This mainly affects large enterprises and institutions that built their data centre on HPE/Aruba hardware: banks, telecommunications operators, energy utilities and larger manufacturing plants. Fabric Composer appears wherever the DC network is managed centrally rather than switch by switch.

AFC instances reachable only from an out-of-band network are less exposed, but patching remains necessary - CVE-2026-19766 requires only adjacent-network access.

Sources


Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.

Learn More

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist