
HPE has released security updates for HPE Networking Fabric Composer following the discovery of a large set of vulnerabilities that could allow unauthenticated attackers to gain administrator access, run arbitrary commands, and fully compromise affected systems. The flaws affect HPE Networking Fabric Composer version 7.3.3 and earlier.
Fabric Composer is used to manage and automate data-center network fabrics, making a successful compromise particularly serious because the platform can control important network infrastructure. The most severe vulnerabilities are tracked as CVE-2026-76657 and CVE-2026-76658. Both received a maximum CVSS score of 10.0.
HPE said the API authentication-bypass flaw, CVE-2026-76657, could allow a remote attacker to circumvent existing authentication controls and obtain administrative privileges without valid credentials. This access could lead to a complete takeover of the Fabric Composer host. CVE-2026-76658 affects the product's SSH daemon.
An unauthenticated remote attacker could exploit the issue to gain administrative access and execute arbitrary commands as…
➪ Continue reading the full article on cybersecuritynews.com









