HPE released security updates for HPE Networking Fabric Composer to remediate multiple vulnerabilities affecting version 7.3.3 and earlier. The most severe, CVE-2026-76657 and CVE-2026-76658 (CVSS 10.0), allow unauthenticated remote attackers to gain administrator access, bypass authentication, execute privileged commands, and fully compromise the Fabric Composer host. CVE-2026-19766 (CVSS 9.6) is an adjacent-network authentication-bypass flaw that can permit privileged arbitrary code execution.
As Fabric Composer manages data-center network fabrics, a successful compromise could let attackers alter network configurations, steal data, and move laterally through affected environments. HPE said it was not aware of public exploit code or public discussion of the flaws at advisory release; organizations should upgrade to the fixed releases and strictly limit access to Fabric Composer management interfaces.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
HPE released security updates for 86 vulnerabilities affecting Aruba Networking AOS-CX and Fabric Composer, including six critical and 46 high-severity flaws with impacts such as remote code execution, authentication bypass, privilege escalation, arbitrary file write, information disclosure, and denial of service. HPE said it will not provide patches or workarounds for end-of-life AOS-CX 10.10.x or Fabric Composer versions that have reached end of maintenance or support.
HPE released security updates for HPE Networking Fabric Composer to remediate numerous flaws affecting version 7.3.3 and earlier, including CVE-2026-76657 and CVE-2026-76658 (CVSS 10.0) and CVE-2026-19766 (CVSS 9.6). The flaws could permit unauthenticated administrative access and privileged code execution; HPE recommended upgrading to fixed releases and restricting management-interface access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
socprime.com
Open sourceacn.gov.it
Open sourcecyberaccord.com
Open sourcecybersecuritynews.com
Open sourcecirt.gy
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.