2w ago
2026-09-01 21:18Z
HIGH

CVE-2026-73779 — Vulnerabilities: have been identified in the operating system of AOS-CX switches that could potentially

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73779

Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could compromise system integrity and further expose sensitive information. CVSSv3.1 8.2 (HIGH)

VNDVulnerabilitiesTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2w ago
2026-09-01 21:18Z
HIGH

CVE-2026-73778 — Credential: A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73778

A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthenticated remote attacker could exploit this vulnerability on a device in its factory-default or post-ZTP state before any administrator has configured credentials by providing a predictable factory-default password. Successful exploitation could result in full administrative control of the affected device during the initial setup process. CVSSv3.1 8.1 (HIGH)

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-09-01 21:18Z
HIGH

CVE-2026-73777 — Vulnerabilities: have been identified in the API endpoint of AOS-CX switches that could potentially

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73777

Vulnerabilities have been identified in the API endpoint of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. CVSSv3.1 8.1 (HIGH)

VNDVulnerabilitiesTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-09-01 21:18Z
HIGH

CVE-2026-73753 — Exploitation: through affected command-line operations could allow an authenticated low-privileged user to execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73753

Exploitation through affected command-line operations could allow an authenticated low-privileged user to execute arbitrary commands as a privileged user on the underlying operating system. CVSSv3.1 8.8 (HIGH)

VNDExploitationTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 21:18Z
HIGH

CVE-2026-73752 — An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73752

An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. Successful exploitation of this vulnerability allows an attacker to write arbitrary files to the underlying operating system, which could lead to remote code execution. CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 21:18Z
HIGH

CVE-2026-73751 — An authenticated user with low-privileged access could submit crafted input through the web-based management

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73751

An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system. CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 21:18Z
HIGH

CVE-2026-73750 — Vulnerabilities: exist in the authentication module that may improperly process malformed or truncated input.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73750

Vulnerabilities exist in the authentication module that may improperly process malformed or truncated input. An authenticated remote attacker could exploit these vulnerabilities by providing specially crafted input from a compromised or hostile authentication server. Successful exploitation could result in a Denial-of-Service or potential remote code execution with elevated privileges. CVSSv3.1 8.8 (HIGH)

VNDVulnerabilitiesTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2w ago
2026-09-01 21:18Z
CRIT

CVE-2026-73749 — Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73749

Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service. Successful exploitation could result in remote code execution with elevated privileges. CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 21:18Z
HIGH

CVE-2026-71981 — Cypht: before 2.12.2 contains a PHP object injection vulnerability that allows authenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71981

Cypht before 2.12.2 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary operating system commands by supplying a crafted PHP object graph in the back_query GET parameter of the logout handler. Attackers can pass a base64-encoded serialized payload through this parameter, which is decoded and passed directly to unserialize() without an allow-list, signature check, or type restriction, enabling gadget-chain exploitation to achi CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDCyphtTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 20:17Z
CRIT

CVE-2026-76658 — A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76658

A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system leading to complete system compromise. CVSSv3.1 10.0 (CRITICAL)

TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2w ago
2026-09-01 20:17Z
CRIT

CVE-2026-76657 — Vulnerabilities: have been identified in the API of HPE Networking Fabric Composer that could

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76657

Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the HPE Networking Fabric Composer host. CVSSv3.1 10.0 (CRITICAL)

VNDVulnerabilitiesTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2w ago
2026-09-01 20:17Z
HIGH

CVE-2026-73712 — API: A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73712

A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise. CVSSv3.1 8.1 (HIGH)

VNDApiTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-09-01 20:17Z
HIGH

CVE-2026-73711 — A privilege escalation vulnerability exists in the API endpoint of HPE Networking Fabric Composer.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73711

A privilege escalation vulnerability exists in the API endpoint of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated remote attacker to gain administrative privileges leading to complete compromise of the HPE Networking Fabric Composer host. CVSSv3.1 8.1 (HIGH)

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-09-01 20:17Z
HIGH

CVE-2026-73710 — Vulnerabilities: in an API endpoint of HPE Networking Fabric Composer could allow an unauthenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73710

Vulnerabilities in an API endpoint of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to make limited unauthorized modifications to the underlying operating system and disrupt the availability of the affected system, requiring manual intervention to restore functionality. CVSSv3.1 8.2 (HIGH)

VNDVulnerabilitiesTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2w ago
2026-09-01 20:17Z
HIGH

CVE-2026-73709 — A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73709

A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an unauthenticated adjacent attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. CVSSv3.1 8.3 (HIGH)

TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2w ago
2026-09-01 20:17Z
HIGH

CVE-2026-73708 — Successful exploitation could allow an authenticated low privilege operator user to obtain elevated privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73708

A business logic vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to obtain elevated privileges and modify settings beyond what is authorized by the user's existing privilege level on a vulnerable system. CVSSv3.1 8.3 (HIGH)

TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2w ago
2026-09-01 20:17Z
HIGH

CVE-2026-73707 — Privilege: escalation vulnerabilities exist in the API of HPE Networking Fabric Composer.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73707

Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to complete state-changing actions that should not be allowed by their current level of authorization on the platform, including changes to the configuration of systems managed by the affected product. CVSSv3.1 8.5 (HIGH)

TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2w ago
2026-09-01 20:17Z
HIGH

CVE-2026-73706 — API: A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73706

A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to obtain limited system information and to change the state of certain settings of a vulnerable system. Successful exploitation could allow an attacker to gain insight into internal services and workflows and to make unauthorized changes that may disrupt the normal operation of the affected service. CVSSv3.1 8.6 (HIGH)

VNDApiTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2w ago
2026-09-01 20:17Z
HIGH

CVE-2026-73705 — An arbitrary file write vulnerability in the API of HPE Networking Fabric Composer could

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73705

An arbitrary file write vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary commands on the underlying operating system, leading to complete compromise of the affected system. CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 20:17Z
HIGH

CVE-2026-73704 — A command sanitization bypass exists in the API of HPE Networking Fabric Composer.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73704

A command sanitization bypass exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escalate their permissions to those of an administrative user, leading to complete compromise of the affected system. CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 20:17Z
HIGH

CVE-2026-73703 — A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73703

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated adjacent attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface. CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 20:17Z
HIGH

CVE-2026-73702 — A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73702

A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escalate their permissions to those of an administrative user, leading to complete system compromise. CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 20:17Z
CRIT

CVE-2026-73701 — An unauthenticated remote code execution vulnerability exists in the underlying operating system of HPE

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73701

An unauthenticated remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer and could be exploited if certain preconditions outside of the attacker's control are met. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to execute arbitrary code as a privileged user on the underlying operating system, leading to complete compromise of the HPE Networking Fabric Composer host. CVSSv3.1 9.0 (CRITICAL)

TYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2w ago
2026-09-01 20:17Z
CRIT

CVE-2026-73700 — A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73700

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface. CVSSv3.1 9.0 (CRITICAL)

TYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2w ago
2026-09-01 20:17Z
HIGH

CVE-2026-72649 — Deserialization: of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72649

Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code execution via Object Injection (CAPEC-586). A specially crafted trained model artifact could cause attacker-controlled logic to execute with a materially broader system-call surface than intended. Exploitation requires an authenticated user with sufficient privileges to create and deploy trained models. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score