VYPR
advisoryPublished Sep 1, 2026· Updated Sep 5, 2026· 1 source

HPE Networking Fabric Composer: 25 Vulnerabilities Including Two Critical Flaws Disclosed Together

Key findings • 25 vulnerabilities disclosed for HPE Networking Fabric Composer on September 1, 2026. • Two critical (CVSS 10.0) vulnerabilities allow unauthenticated remote code execution and…

Key findings

  • 25 vulnerabilities disclosed for HPE Networking Fabric Composer on September 1, 2026.
  • Two critical (CVSS 10.0) vulnerabilities allow unauthenticated remote code execution and administrative access.
  • Flaws affect SSH daemon and API, enabling command execution and authentication bypass.
  • Medium and low severity issues include privilege escalation, information disclosure, and DoS.
  • HPE released security updates, patching versions 7.3.3 and earlier.

On September 1, 2026, a significant batch of 25 vulnerabilities was disclosed for HPE Networking Fabric Composer. This coordinated disclosure event, spanning a single day, revealed flaws ranging in severity from Low to Critical, with two critical vulnerabilities (CVE-2026-76658 and CVE-2026-76657) carrying a CVSSv3 score of 10.0. These critical flaws, in particular, could allow unauthenticated remote attackers to gain administrative access and execute arbitrary commands, posing a severe risk to network infrastructure managed by the Fabric Composer.

The vulnerabilities can be broadly categorized by their impact and the component they affect. Two critical vulnerabilities, CVE-2026-76658 and CVE-2026-76657, stand out. CVE-2026-76658 targets the SSH daemon, potentially granting administrative access and enabling arbitrary command execution. CVE-2026-76657 affects the API, allowing unauthenticated attackers to bypass authentication controls and achieve complete system compromise.

Several medium-severity vulnerabilities also present significant risks. CVE-2026-73726, for instance, involves an underlying operating system vulnerability that could allow an unauthenticated adjacent actor to bypass authentication and gain administrative access. Other medium-severity flaws include privilege escalation (CVE-2026-73740, CVE-2026-73730, CVE-2026-73721), information disclosure through cleartext or unauthorized file access (CVE-2026-73748, CVE-2026-73743, CVE-2026-73741, CVE-2026-73739, CVE-2026-73736, CVE-2026-73738, CVE-2026-73733, CVE-2026-73732, CVE-2026-73729, CVE-2026-73727), and denial-of-service conditions (CVE-2026-73745, CVE-2026-73744, CVE-2026-73728). Additionally, vulnerabilities related to path traversal (CVE-2026-73737) and URL redirection (CVE-2026-73734) were disclosed.

Low-severity vulnerabilities, while less impactful individually, contribute to the overall risk landscape. These include local privilege escalation (CVE-2026-73747), denial-of-service (CVE-2026-73746, CVE-2026-73744), and information disclosure (CVE-2026-73748, CVE-2026-73747, CVE-2026-73745, CVE-2026-73743, CVE-2026-73736).

The critical vulnerabilities, CVE-2026-76657 and CVE-2026-76658, have been highlighted by cybersecurity news outlets as particularly concerning, with the potential for unauthenticated attackers to execute code and take over systems. The affected product, HPE Networking Fabric Composer, is crucial for managing and automating data-center network fabrics, making a compromise of this platform particularly serious due to its control over critical network infrastructure.

HPE has released security updates to address these vulnerabilities. The critical flaws were patched in version 7.3.3 and earlier versions are affected. Users are strongly advised to update to the latest version to mitigate the risks associated with these numerous vulnerabilities.

This extensive batch of vulnerabilities underscores the importance of timely patching and security updates for network management platforms. The wide range of severity and impact across different components of HPE Networking Fabric Composer highlights the need for a comprehensive security strategy, including regular audits and prompt remediation of discovered flaws. Users should prioritize updating their systems to the patched versions to protect their network infrastructure from potential compromise.

Synthesized by Vypr AI