ZeroHour

Vulnerabilities

597 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-76658
Unauthenticated SSH flaw in HPE Aruba Fabric Composer allows admin takeover

HPE Aruba Fabric Composer (AFC) contains an improper authentication flaw (CWE-287) in its SSH daemon that allows an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. The flaw is triggered simply by connecting to the SSH service exposed by the Fabric Composer host over the network, with no credentials or user interaction required. A successful attacker can execute arbitrary commands as a privileged user on the underlying operating system, leading to complete compromise of the AFC management host. Any organization running HPE Aruba Fabric Composer — orchestration software typically deployed in enterprise and data center environments — is potentially affected, though exposure depends on whether the SSH daemon is reachable from untrusted networks. As of now there is no known public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS puts 30-day exploitation probability at only 0.4%, so no active exploitation is known.

Do: Restrict SSH access to Fabric Composer hosts so only trusted management networks can reach the SSH daemon, and monitor the HPE/Aruba security advisory for the patched release, since affected and fixed version numbers are not stated in this data. Once HPE publishes a fix, upgrade affected AFC hosts promptly; meanwhile treat any AFC host whose SSH port is reachable from untrusted networks as at risk.

10.0
group max
<1%
  • HPE (Aruba Networks) Aruba Fabric Composer (AFC)
nicheestimated low thousands of AFC management-host deployments worldwide; unknown precisely