← Back to overview

A critical vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer (AFC). The flaw allows an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts without any credentials. Successful exploitation enables execution of arbitrary commands as a privileged user on the underlying operating system. This can lead to complete system compromise of affected HPE AFC hosts. The vulnerability is tracked as CVE-2026-76658 and has been assigned a high criticality rating. HPE has published a security bulletin providing remediation guidance. The attack vector is remote and requires no authentication, significantly raising its risk profile. Organizations using HPE Networking Fabric Composer are urged to apply patches immediately.

Affected products

  • HPE Networking Fabric Composer

Related CVE's

  • CVE-2026-76658

Categories

  • Identity & Access
  • Network Infrastructure
  • Zero-Day Vulnerabilities