CVE-2026-19766: Arubanetworks Fabric Composer

Critical severity, CVSS 9.6. EPSS: 0.3% chance of exploitation in the next 30 days.

An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated adjacent attacker to execute arbitrary code as a privileged user on the underlying operating system, leading to complete compromise of the AFC host.

Affected products

  • Arubanetworks Fabric Composer: from 7.0.0, up to and including 7.3.3

Published 2026-09-01. Last modified 2026-09-04.