Skip to content
VulniPulse

HPE Aruba Networking Fabric Composer Vulnerabilities & Security Advisories

57 advisories tracked · HPE Aruba Networking Security Advisories (PSIRT) via NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published HPE Aruba Networking advisory that VulniPulse classified as Fabric Composer, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 5 critical, 26 high, 20 medium, 6 low.

Android app · Google Play

Monitor Aruba CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

HPE Aruba Networking Security Advisories (PSIRT) via NVD

Aruba's PSIRT bulletin portal (arubanetworks.com) is a JavaScript app with no stable public feed, so VulniPulse ingests Aruba's CVEs from NVD. Aruba publishes under the shared HPE CNA (security-alert@hpe.com), which also covers non-networking HPE products — so this feed is filtered to the full HPE Aruba Networking portfolio: ClearPass, AOS-8 mobility controllers, AOS-10 gateways and APs, Instant APs, AOS-CX and legacy AOS-Switch, Aruba Central, Fabric Composer and EdgeConnect/Silver Peak SD-WAN. Each entry links back to the official Aruba/HPE advisory when NVD carries the reference.

Latest Aruba Fabric Composer advisories

Critical10.0Aruba

Critical [CVE-2026-76658] Fabric Composer: vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts

A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system leading to complete system compromise.

CVE-2026-76658
Fabric Composer
Sep 1, 2026
Critical10.0Aruba

Critical [CVE-2026-76657] Fabric Composer: Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls

Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the HPE Networking Fabric Composer host.

CVE-2026-76657
Fabric Composer
Sep 1, 2026
Critical9.0Aruba

Critical [CVE-2026-73701] Unauthenticated Remote Code Execution in HPE Networking Fabric Composer

An unauthenticated remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer and could be exploited if certain preconditions outside of the attacker's control are met. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to execute arbitrary code as a privileged user on the underlying operating system, leading to complete compromise of the HPE Networking Fabric Composer host.

CVE-2026-73701
Fabric Composer
Sep 1, 2026
Critical9.0Aruba

Critical [CVE-2026-73700] Authenticated Stored Cross-Site Scripting Vulnerability (XSS) in HPE Networking Fabric Composer Web-Based Management Interface

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.

CVE-2026-73700
Fabric Composer
Sep 1, 2026
Critical9.6Aruba

Critical [CVE-2026-19766] Authentication Bypass leads to Administrative control of adjacent network hosts in HPE Networking Fabric Composer

An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated adjacent attacker to execute arbitrary code as a privileged user on the underlying operating system, leading to complete compromise of the AFC host.

CVE-2026-19766
Fabric Composer
Sep 1, 2026
High7.0Aruba

High [CVE-2026-73725] Fabric Composer: local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer

A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges, leading to a complete compromise of the affected host.

CVE-2026-73725
Fabric Composer
Sep 1, 2026
High7.1Aruba

High [CVE-2026-73724] Fabric Composer: Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer

Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulnerable system.

CVE-2026-73724
Fabric Composer
Sep 1, 2026
High7.1Aruba

High [CVE-2026-73723] Fabric Composer: privilege escalation vulnerability exists in the web-based management interface of HPE Networking Fabric Composer

A privilege escalation vulnerability exists in the web-based management interface of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to complete state-changing actions that should not be allowed by their current level of authorization on the platform.

CVE-2026-73723
Fabric Composer
Sep 1, 2026
High7.2Aruba

High [CVE-2026-73722] Fabric Composer: Command injection vulnerabilities in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated remote attacker to perform command injection against the affected system

Command injection vulnerabilities in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated remote attacker to perform command injection against the affected system. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.

CVE-2026-73722
Fabric Composer
Sep 1, 2026
High7.2Aruba

High [CVE-2026-73721] Fabric Composer: Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated remote attacker to conduct SQL injection attacks against the HPE Networking Fabric Composer instance

Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated remote attacker to conduct SQL injection attacks against the HPE Networking Fabric Composer instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database potentially leading to complete compromise of the HPE Networking Fabric Composer host.

CVE-2026-73721
Fabric Composer
Sep 1, 2026
High7.2Aruba

High [CVE-2026-73720] Fabric Composer: Insecure file operations in the API of HPE Networking Fabric Composer could allow an authenticated remote attacker to achieve remote code execution

Insecure file operations in the API of HPE Networking Fabric Composer could allow an authenticated remote attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.

CVE-2026-73720
Fabric Composer
Sep 1, 2026
High7.2Aruba

High [CVE-2026-73719] Authenticated Arbitrary File Write Vulnerability leads to Remote Code Execution in HPE Networking Fabric Composer

An arbitrary file write vulnerability exists in the API of HPE Networking Fabric Composer and could allow an authenticated administrative user to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying operating system.

CVE-2026-73719
Fabric Composer
Sep 1, 2026
High7.4Aruba

High [CVE-2026-73718] Unauthenticated Information Disclosure in Web Interface allows Sensitive Data Exposure in HPE Networking Fabric Composer

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to access sensitive information if the attacker can convince an authenticated user of the interface to interact with a specially crafted URL. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking Fabric Composer.

CVE-2026-73718
Fabric Composer
Sep 1, 2026
High7.5Aruba

High [CVE-2026-73717] Unauthenticated Command Injection Vulnerability in HPE Networking Fabric Composer Web-Based Management Interface

A command injection vulnerability exists in the web-based management interface of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

CVE-2026-73717
Fabric Composer
Sep 1, 2026
High7.5Aruba

High [CVE-2026-73716] Unauthenticated Remote Code Execution in HPE Networking Fabric Composer

A remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system, leading to complete compromise of the HPE Networking Fabric Composer host.

CVE-2026-73716
Fabric Composer
Sep 1, 2026
High7.5Aruba

High [CVE-2026-73715] Unauthenticated Denial-of-Service (DoS) Vulnerability in the API of HPE Networking Fabric Composer

A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to disrupt the availability of the affected interface.

CVE-2026-73715
Fabric Composer
Sep 1, 2026
High7.6Aruba

High [CVE-2026-73714] Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer API

A sensitive information disclosure vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to access data beyond what is authorized by the user's existing privilege level, potentially leading to further unauthorized access.

CVE-2026-73714
Fabric Composer
Sep 1, 2026
High7.8Aruba

High [CVE-2026-73713] Local Privilege Escalation Vulnerabilities in HPE Networking Fabric Composer

Local privilege-escalation vulnerabilities have been discovered in HPE Networking Fabric Composer. Successful exploitation of these vulnerabilities could allow a local attacker to achieve arbitrary code execution with root privileges on the underlying operating system of the affected system.

CVE-2026-73713
Fabric Composer
Sep 1, 2026
High8.1Aruba

High [CVE-2026-73712] Unauthenticated Remote Code Execution in HPE Networking Fabric Composer API

A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

CVE-2026-73712
Fabric Composer
Sep 1, 2026
High8.1Aruba

High [CVE-2026-73711] Unauthenticated Privilege Escalation allows Administrative Access in HPE Networking Fabric Composer API

A privilege escalation vulnerability exists in the API endpoint of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated remote attacker to gain administrative privileges leading to complete compromise of the HPE Networking Fabric Composer host.

CVE-2026-73711
Fabric Composer
Sep 1, 2026

← All Aruba advisories