T
Threats
HPE Networking Fabric Composer Critical Vulnerabilities
Overview
CVE: CVE-2026-76657, CVE-2026-76658, CVE-2026-19766, CVE-2026-73700, CVE-2026-73701
Severity: Critical
Date: 1 September 2026
HPE has released security updates for HPE Networking Fabric Composer to address five critical vulnerabilities. Depending on the flaw, successful exploitation could allow an unauthenticated attacker to bypass authentication, obtain administrative access, or execute privileged code or commands. One vulnerability requires adjacent network access, while another requires a low-privilege operator account and interaction by an administrative user.
Affected Versions
HPE Networking Fabric Composer 7.3.x
Affected: 7.3.3 and below
Fixed: 7.3.4 and above
Not affected: 7.3.4 and above
HPE Networking Fabric Composer 7.4.x
Affected: No affected 7.4.x release is listed in the advisory
Fixed: 7.4.0 and above
Not affected: 7.4.0 and above
Vulnerability Breakdown
CVE-2026-76657 - API Authentication Bypass
Severity: Critical
CVSS: 10.0
Description: Vulnerabilities in the Fabric Composer API could allow an unauthenticated remote attacker to circumvent existing authentication controls.
Impact: Administrative privileges and complete compromise of the Fabric Composer host.
Conditions: Remote network access. No authentication is required.
CVE-2026-76658 - SSH Daemon Authentication Bypass
Severity: Critical
CVSS: 10.0
Description: A vulnerability in the Fabric Composer SSH daemon could allow an unauthenticated remote attacker to gain administrative access to a vulnerable host.
Impact: Arbitrary command execution as a privileged user, leading to complete system compromise.
Conditions: Remote network access. No authentication is required.
CVE-2026-19766 - Operating System Authentication Bypass
Severity: Critical
CVSS: 9.6
Description: An authentication bypass vulnerability in the underlying operating system could allow an unauthenticated adjacent attacker to execute arbitrary code.
Impact: Privileged code execution and complete compromise of the Fabric Composer host.
Conditions: The attacker must have adjacent network access. No authentication is required.
CVE-2026-73700 - Stored Cross-Site Scripting
Severity: Critical
CVSS: 9.0
Description: A flaw in the web-based management interface could allow an authenticated low-privilege operator to store malicious script content that executes in an administrative user's browser.
Impact: Arbitrary script execution in the context of the affected management interface.
Conditions: A low-privilege operator account and interaction by an administrative user are required.
CVE-2026-73701 - Remote Code Execution
Severity: Critical
CVSS: 9.0
Description: A vulnerability in the underlying operating system could allow unauthenticated remote code execution when certain preconditions outside the attacker's control are met.
Impact: Arbitrary code execution as a privileged user and complete compromise of the Fabric Composer host.
Conditions: No authentication is required, but specific environmental preconditions must be met.
Mitigation
Upgrade HPE Networking Fabric Composer 7.3.x deployments to version 7.3.4 or later.
Alternatively, upgrade to HPE Networking Fabric Composer 7.4.0 or later.
Prioritise internet-facing or broadly accessible management deployments because multiple flaws require no authentication.
Confirm the installed version after remediation and monitor administrative and SSH access for suspicious activity.
Summary for IT Teams
Products: HPE Networking Fabric Composer
Threat Level: Critical, CVSS up to 10.0
Action Required: Upgrade affected Fabric Composer deployments to 7.3.4 or later, or to 7.4.0 or later, as soon as possible.
Reference
Need Help?
Secure ISS can help your organisation assess exposure, plan remediation, and validate HPE Networking Fabric Composer updates. Contact the Secure ISS SOC team on 1300 769 460.

