CTIPilot

HPE Networking Fabric Composer SSH daemon unauthenticated RCE (CVSS 10.0)

cve · CVE-2026-76658 single-source

Coverage timeline
1
first 2026-09-04 → last 2026-09-04
Peak priority
high
1 high
Sources cited
7
4 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
8
see Co-occurring entities below
ATT&CK techniques
1
pinned v19.2 · see below

ATT&CK techniques

1 technique observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-09-04/hpe-aruba-fabric-composer-arubaos-cx-cvss10-bundle · ATT&CK page ↗

Story timeline

  1. 2026-09-04HPE Networking Fabric Composer and ArubaOS-CX: two unauthenticated CVSS 10.0 RCEs in the fabric-management plane, plus a CVSS 9.8 unauthenticated buffer-overflow RCE in the switch OS
    trending-vulnerabilitiesHPE patches unauthenticated administrative-takeover flaws in the controller that manages Aruba switch fabrics, and a separate pre-auth RCE in ArubaOS-CX itself

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • cveawg.mitre.org3 (43%)
  • advisories.ncsc.nl2 (29%)
  • bleepingcomputer.com1 (14%)
  • cert.ssi.gouv.fr1 (14%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about HPE Networking Fabric Composer SSH daemon unauthenticated RCE (CVSS 10.0) (1)

2026-09-04 · view entry permalink →

HIGHCVE-2026-76658 +8updatedNATOA2

HPE Networking Fabric Composer and ArubaOS-CX: two unauthenticated CVSS 10.0 RCEs in the fabric-management plane, plus a CVSS 9.8 unauthenticated buffer-overflow RCE in the switch OS

HPE published two Aruba Networking security bulletins in the same release window: Fabric Composer bulletin HPESBNW05133 on 2026-09-01, and an ArubaOS-CX bulletin around the same date, both picked up by NCSC-NL and CERT-FR on 2026-09-02/03. HPE Networking Fabric Composer (AFC), the controller that manages Aruba CX switch fabrics, carries 45 CVEs in one bulletin (NCSC-NL, 2026-09-03), two of them CVSS 10.0: CVE-2026-76658 is an authentication weakness in AFC's SSH daemon that lets an unauthenticated remote attacker connect with no credentials, user interaction or preparation and execute arbitrary commands as a privileged operating-system user (HPE, via MITRE CVE record, 2026-09-01); CVE-2026-76657 is an API authentication-bypass flaw letting an unauthenticated attacker circumvent AFC's API auth controls and obtain administrative privileges. Three more rank Critical: CVE-2026-19766 (9.6, adjacent-network auth bypass to privileged code execution on the underlying OS), CVE-2026-73701 (9.0, unauthenticated privileged RCE with unspecified preconditions) and CVE-2026-73700 (9.0, authenticated stored cross-site scripting reachable by a low-privilege operator against an admin). Fixed in Fabric Composer 7.4.0 (or 7.3.4 for the 7.3 branch); every 7.3.3-and-earlier install is affected, all discovered by HPE's own internal Networking security research team.

Separately, ArubaOS-CX (the network OS on Aruba's CX-series campus and data-center switches) carries CVE-2026-73749 (CVSS 9.8): a buffer overflow in an unnamed AOS-CX daemon that an unauthenticated remote attacker triggers by sending specially crafted packets, reaching remote code execution with elevated privileges (HPE, via MITRE CVE record, 2026-09-01). Affected release branches and fixes, per HPE's bulletin: the 10.18 branch up to and including 10.18.0001, fixing to 10.18.1002+, 10.17.1021 and earlier fix to 10.17.1030+, 10.16.1051 and earlier fix to 10.16.1060+, 10.13.1180 and earlier fix to 10.13.1190+, and 10.10.1180 and earlier fix to 10.10.1181+, that last branch is already past HPE's End of Maintenance and receives only critical-severity fixes, a category this CVE qualifies for. The same ArubaOS-CX bulletin lists further CVEs including an unauthenticated adjacent-network arbitrary file write via an API endpoint (CVE-2026-73752, 8.8), an unauthenticated format-string flaw in the CLI reachable from an adjacent network (CVE-2026-73782, 8.8), and an unauthenticated predictable factory-default password (CVE-2026-73778, 8.1) granting full admin control on a switch before an administrator sets credentials after Zero-Touch Provisioning. The exact further-CVE count is unresolved between this entry's two cited sources: BleepingComputer's account of HPE's own bulletin states "23 other security vulnerabilities...between 8.1 and 8.8" (BleepingComputer, 2026-09-03), and its list names at least one identifier (CVE-2026-73781, an authenticated stored XSS) absent from NCSC-NL's independently-mirrored structured advisory data for the same bulletin, which lists 25 further CVEs spanning a wider 4.9-8.8 range (NCSC-NL, 2026-09-03); HPE's own bulletin page sits behind a support-portal login wall this entry could not read directly to resolve the discrepancy. HPE states it is not aware of active exploitation or public proof-of-concept for either bulletin's flaws.

A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system leading to complete system compromise.

Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service.

MITRE CVE Program (HPE as CNA) 2026-09-01
Correctionrun 2026-09-06T1308Z-auditcvesbody

The affected range this entry recorded for CVE-2026-73749's 10.18 branch was inverted. HPE's own CVE record, published through MITRE as the CNA, states the affected AOS-CX versions as 10.18.0000 up to and including 10.18.0001 (HPE, via MITRE CVE record, 2026-09-01); BleepingComputer's reading of HPE's bulletin agrees, listing the branch as "10.18.0001 → upgrade to 10.18.1002+" (BleepingComputer, 2026-09-03). 10.18.0001 is therefore the last affected build on that branch, not the first, and the upper bound 10.18.1001 appears in neither source.

What this changes for a defender: a switch running 10.18.0000 is in scope for this unauthenticated remote code execution and would have read the previous range as beginning above its own version. The fixed release for the branch, 10.18.1002 or later, is unchanged, as are the 10.17, 10.16, 10.13 and 10.10 branches.

vulnerability04 Sep 05:20Zsingle-sourceOpen finding ↗