Critical CVE-2026-76658 Vulnerability in HPE Fabric Composer

Critical CVE-2026-76658 Vulnerability in HPE Fabric Composer

First seen 2 Sep 2026, 22:13 UTC GbhackersSocprime 72.0

Article Content

Browse articles
ThreatCluster

Hewlett Packard Enterprise (HPE) has issued security updates for a critical remote code execution vulnerability, CVE-2026-76658, affecting its Networking Fabric Composer. This flaw, rated 10.0 on the CVSS scale, allows unauthenticated attackers to execute arbitrary commands as a privileged user. The vulnerability resides in the SSH daemon of the Fabric Composer, impacting versions 7.3.3 and earlier. HPE's advisory indicates that successful exploitation could lead to complete system compromise, posing a significant risk to network infrastructure management. HPE has not reported any public exploit code or discussions targeting this vulnerability. Organizations are urged to upgrade to version 7.3.4 or later to mitigate the risk. This vulnerability is part of a broader advisory covering 52 vulnerabilities, including another critical flaw, CVE-2026-76657. The urgency for remediation is heightened due to the low complexity of the attack and the potential for high impact across confidentiality, integrity, and availability.

Key Points: • CVE-2026-76658 allows unauthenticated remote code execution on HPE Fabric Composer. • The vulnerability affects versions 7.3.3 and earlier, with a CVSS score of 10.0. • HPE recommends immediate upgrades to mitigate risks associated with this flaw.

Timeline

2026-09-01
CVE-2026-76658 published
HPE disclosed a critical remote code execution vulnerability in HPE Networking Fabric Composer, affecting versions 7.3.3 and earlier.
Socprime
2026-09-01
CVE-2026-76657 published
HPE also disclosed another critical flaw allowing unauthenticated API authentication bypass, also rated 10.0.
Socprime
2026-09-01
CVE-2026-19766 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-02
HPE issues security updates
HPE released updates addressing the critical vulnerabilities, urging organizations to upgrade to version 7.3.4 or later.
Gbhackers