Description

HPE Aruba Networking has issued an urgent security advisory warning customers to immediately update their Fabric Composer software after identifying multiple serious vulnerabilities. Fabric Composer, which is widely used to streamline and automate network provisioning, was found to contain flaws that could expose systems to severe compromise. The most critical issue allows attackers to gain control over the underlying operating system, posing a significant risk to enterprise network environments if left unpatched. Administrators running vulnerable versions are strongly encouraged to take action without delay. The most severe vulnerability, tracked as CVE-2026-23592, is a high-severity Remote Code Execution (RCE) flaw rooted in unsafe file handling within the backup feature. An authenticated attacker could exploit this weakness to run arbitrary commands on the host system, potentially leading to full system takeover. Although authentication is required, the impact of successful exploitation is considered extremely dangerous. In addition, the update resolves a high-severity OpenSSL issue (CVE-2024-4741) involving a “use-after-free” condition, which could be abused under certain conditions to destabilize or compromise secure communications. A third issue, CVE-2026-23593, is a medium-severity information disclosure vulnerability affecting the web management interface. This flaw could allow unauthenticated attackers to access limited system files. To address all three issues, HPE Aruba Networking has released Fabric Composer version 7.3.0 and later. Organizations unable to patch immediately are advised to limit access to management interfaces through network segmentation and strict firewall controls.