# HPE releases fixes for critical Fabric Composer flaws

_Wednesday, September 2, 2026 at 4:27 AM EDT · Security · Latest · Tier 2 — Notable_

![HPE releases fixes for critical Fabric Composer flaws — Primary](https://cyberpress.org/wp-content/uploads/2026/09/Critical-HPE-Fabric-Composer-Flaw-Lets-Unauthenticated-Attackers-Execute-Commands-as-Root.webp)

HPE Networking released security updates for Fabric Composer after disclosing vulnerabilities including CVE-2026-76658, which its advisory says can let an unauthenticated remote attacker execute commands as a privileged operating-system user through the SSH daemon. A second critical flaw, CVE-2026-76657, can bypass authentication through the API and grant administrative privileges. The advisory covers version 7.3.3 and earlier; HPE recommends 7.4.0 or later on the 7.4 branch, or 7.3.4 or later on 7.3.

## Sources

- [cyberpress.org](https://cyberpress.org/critical-hpe-fabric-composer-flaw/)

---
Canonical: https://techandbusiness.org/newswire/ONHw39TwSVwGaO-bLIxcdc
Retrieved: 2026-09-02T13:07:37.880Z
Publisher: Tech & Business (techandbusiness.org)
