2026-09-04 · view entry permalink →
HPE Networking Fabric Composer and ArubaOS-CX: two unauthenticated CVSS 10.0 RCEs in the fabric-management plane, plus a CVSS 9.8 unauthenticated buffer-overflow RCE in the switch OS
HPE published two Aruba Networking security bulletins in the same release window: Fabric Composer bulletin HPESBNW05133 on 2026-09-01, and an ArubaOS-CX bulletin around the same date, both picked up by NCSC-NL and CERT-FR on 2026-09-02/03. HPE Networking Fabric Composer (AFC), the controller that manages Aruba CX switch fabrics, carries 45 CVEs in one bulletin (NCSC-NL, 2026-09-03), two of them CVSS 10.0: CVE-2026-76658 is an authentication weakness in AFC's SSH daemon that lets an unauthenticated remote attacker connect with no credentials, user interaction or preparation and execute arbitrary commands as a privileged operating-system user (HPE, via MITRE CVE record, 2026-09-01); CVE-2026-76657 is an API authentication-bypass flaw letting an unauthenticated attacker circumvent AFC's API auth controls and obtain administrative privileges. Three more rank Critical: CVE-2026-19766 (9.6, adjacent-network auth bypass to privileged code execution on the underlying OS), CVE-2026-73701 (9.0, unauthenticated privileged RCE with unspecified preconditions) and CVE-2026-73700 (9.0, authenticated stored cross-site scripting reachable by a low-privilege operator against an admin). Fixed in Fabric Composer 7.4.0 (or 7.3.4 for the 7.3 branch); every 7.3.3-and-earlier install is affected, all discovered by HPE's own internal Networking security research team.
Separately, ArubaOS-CX (the network OS on Aruba's CX-series campus and data-center switches) carries CVE-2026-73749 (CVSS 9.8): a buffer overflow in an unnamed AOS-CX daemon that an unauthenticated remote attacker triggers by sending specially crafted packets, reaching remote code execution with elevated privileges (HPE, via MITRE CVE record, 2026-09-01). Affected release branches and fixes, per HPE's bulletin: the 10.18 branch up to and including 10.18.0001, fixing to 10.18.1002+, 10.17.1021 and earlier fix to 10.17.1030+, 10.16.1051 and earlier fix to 10.16.1060+, 10.13.1180 and earlier fix to 10.13.1190+, and 10.10.1180 and earlier fix to 10.10.1181+, that last branch is already past HPE's End of Maintenance and receives only critical-severity fixes, a category this CVE qualifies for. The same ArubaOS-CX bulletin lists further CVEs including an unauthenticated adjacent-network arbitrary file write via an API endpoint (CVE-2026-73752, 8.8), an unauthenticated format-string flaw in the CLI reachable from an adjacent network (CVE-2026-73782, 8.8), and an unauthenticated predictable factory-default password (CVE-2026-73778, 8.1) granting full admin control on a switch before an administrator sets credentials after Zero-Touch Provisioning. The exact further-CVE count is unresolved between this entry's two cited sources: BleepingComputer's account of HPE's own bulletin states "23 other security vulnerabilities...between 8.1 and 8.8" (BleepingComputer, 2026-09-03), and its list names at least one identifier (CVE-2026-73781, an authenticated stored XSS) absent from NCSC-NL's independently-mirrored structured advisory data for the same bulletin, which lists 25 further CVEs spanning a wider 4.9-8.8 range (NCSC-NL, 2026-09-03); HPE's own bulletin page sits behind a support-portal login wall this entry could not read directly to resolve the discrepancy. HPE states it is not aware of active exploitation or public proof-of-concept for either bulletin's flaws.
A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system leading to complete system compromise.
Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service.
The affected range this entry recorded for CVE-2026-73749's 10.18 branch was inverted. HPE's own CVE record, published through MITRE as the CNA, states the affected AOS-CX versions as 10.18.0000 up to and including 10.18.0001 (HPE, via MITRE CVE record, 2026-09-01); BleepingComputer's reading of HPE's bulletin agrees, listing the branch as "10.18.0001 → upgrade to 10.18.1002+" (BleepingComputer, 2026-09-03). 10.18.0001 is therefore the last affected build on that branch, not the first, and the upper bound 10.18.1001 appears in neither source.
What this changes for a defender: a switch running 10.18.0000 is in scope for this unauthenticated remote code execution and would have read the previous range as beginning above its own version. The fixed release for the branch, 10.18.1002 or later, is unchanged, as are the 10.17, 10.16, 10.13 and 10.10 branches.