← All briefings

HPE Networking Fabric Composer · Team Password Manager · Elastic Elasticsearch

Date: 2026-09-02 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership

Executive Summary

New EUVD records identify critical authentication and remote-code-execution risks in HPE Networking Fabric Composer, including unauthenticated administrative access, and a critical unauthenticated password-reset flaw in Team Password Manager. Langflow exploitation has materially escalated: attackers are reportedly using the flaw to steal OpenAI and AWS credentials. A BGP hijacking campaign also delivered malicious Virtualizor updates, creating supply-chain risk for VPS operators.

Critical Vulnerabilities

CVE-2026-76658 — HPE Networking Fabric Composer

  • Severity: CVSS 10.0
  • EPSS: 0 — no elevated exploitation probability estimate available
  • Technical detail: An SSH-daemon vulnerability in Fabric Composer 7.0.0 through 7.3.3 may allow an unauthenticated remote attacker to gain administrative access to affected AFC hosts. This is a direct management-plane compromise risk where the service is reachable from untrusted or broadly accessible networks.
  • Exploitation status: No confirmed exploitation reported in the supplied data.
  • Remediation: Apply HPE’s fixed release immediately. Restrict SSH and management interfaces to trusted administration networks, review administrative logins and configuration changes, and rotate credentials if exposure or compromise is suspected.

CVE-2026-76657 — HPE Networking Fabric Composer

  • Severity: CVSS 10.0
  • EPSS: 0 — no elevated exploitation probability estimate available
  • Technical detail: Vulnerabilities in the Fabric Composer API permit unauthenticated attackers to bypass existing authentication controls. Successful exploitation could expose or modify management functions, with risk amplified by the product’s role in network fabric administration.
  • Exploitation status: No confirmed exploitation reported in the supplied data.
  • Remediation: Upgrade Fabric Composer 7.0.0–7.3.3 deployments to the vendor-fixed version. Remove direct internet exposure, enforce network-layer access controls and inspect API authentication and administrative activity.

CVE-2026-73701 — HPE Networking Fabric Composer

  • Severity: CVSS 9.0
  • EPSS: Not available
  • Technical detail: An unauthenticated remote code-execution vulnerability affects the underlying operating system of Fabric Composer 7.0.0 through 7.3.3. Exploitation requires additional preconditions that are not specified in the supplied data, but successful exploitation could compromise the management host.
  • Exploitation status: No confirmed exploitation reported in the supplied data.
  • Remediation: Apply HPE updates and isolate the management host. Hunt for unexpected processes, persistence, outbound connections and changes to system or application files.

CVE-2026-84699 — Team Password Manager

  • Severity: CVSS 9.3
  • EPSS: Not available
  • Technical detail: Versions before 14.184.308 fail to enforce authentication requirements in the local-account password-reset flow. An unauthenticated attacker may reset local account passwords and authenticate as those users, potentially exposing stored enterprise credentials.
  • Exploitation status: No confirmed exploitation reported in the supplied data.
  • Remediation: Upgrade to 14.184.308 or later immediately. Review password-reset events, newly authenticated sessions and access to stored secrets; force password resets and rotate managed credentials if the instance was internet-exposed or suspicious activity is identified.

CVE-2026-72649 — Elastic Elasticsearch

  • Severity: CVSS 8.8
  • EPSS: Not available
  • Technical detail: Unsafe deserialisation in the Elasticsearch machine-learning component can lead to remote code execution through a specially crafted trained-model artifact. Affected versions include Elasticsearch 8.0.0 through 8.19.19, 9.0.0 through 9.4.4 and 9.5.0; exploitation depends on the target processing an attacker-controlled model artifact.
  • Exploitation status: No confirmed exploitation reported in the supplied data.
  • Remediation: Upgrade to the vendor-fixed release. Restrict model-artifact ingestion and machine-learning administration, review recently uploaded or imported models and monitor Elasticsearch hosts for unexpected process execution.

ONGOING:

  • CVE-2026-82329 (JFrog Artifactory): actively exploited to mint administrator tokens; patch immediately and investigate authentication-bypass activity.
  • CVE-2026-81578 / CVE-2026-82078 (PaperCut NG/MF): actively exploited chained attack path; patch before the 2026-09-14 KEV deadline and hunt for Java execution and data theft.
  • CVE-2026-63520 (Microsoft SharePoint): active exploitation and public PoC remain reported; patch and inspect for web shells.
  • CVE-2026-8452 (Citrix NetScaler ADC/Gateway): actively exploited; verify patching and management-interface restrictions.
  • CVE-2026-60004 (Gitea): KEV remediation deadline passed; patch and inspect Git hook directories.
  • CVE-2023-49105 (ownCloud), CVE-2026-19478 (GitLab), CVE-2019-1068 (Microsoft SQL Server), CVE-2026-53362 (Linux Kernel): active or KEV-listed remediation remains required.

European Advisories

  • CERT-Bund WID-SEC-2026-1190GNU libc: Updated critical advisory covering remote exploitation that may enable file manipulation, denial of service or other impacts. Review distribution updates and prioritise externally reachable services.
  • CERT-Bund WID-SEC-2026-1812Kemp LoadMaster: Updated critical advisory covering security-control bypass, data manipulation and arbitrary code execution. Verify appliance versions and restrict management access.
  • CERT-Bund WID-SEC-2026-2784Microsoft Exchange Server: Updated high-severity advisory involving privilege escalation to SYSTEM, code execution, security-control bypass and data exposure. Apply applicable Microsoft updates and validate internet-facing Exchange exposure.
  • CERT-Bund issued additional updates for Linux Kernel, GnuTLS, cURL, OpenShift, xz, Vim, Ansible, Docker, BIND, Atlassian products, MySQL, PostgreSQL, libssh and rsyslog. Review these against existing maintenance plans; no new CVE-level details were supplied.
  • The HPE Fabric Composer and AOS-CX vulnerabilities reported through EUVD are covered in Critical Vulnerabilities.

Active Threats and Campaigns

  • Langflow exploitation — STATUS CHANGE: Attackers are exploiting CVE-2026-0768, reportedly stealing OpenAI and AWS keys from vulnerable deployments. Bleeping Computer Patch immediately, revoke exposed cloud credentials and investigate flow-execution, outbound network and secret-access logs.
  • Virtualizor malicious update — NEW: Attackers hijacked BGP routing for the Virtualizor update infrastructure and redirected update requests to malicious servers. Bleeping Computer Validate update provenance, compare installed packages with trusted hashes and review VPS management hosts for persistence.
  • Faronics Deploy / ScreenConnect abuse — NEW: Phishing actors are abusing Faronics Deploy for remote administrative access and ScreenConnect installation. Bleeping Computer Hunt for unexpected Deploy activity, ScreenConnect services and new remote-admin sessions.
  • BREEZE COMET — ONGOING: Financially motivated payment-system compromises remain reported in Brazil; European targeting is unconfirmed.

Security News and Context

  • Approximately 5,000 Dropbox accounts without MFA were reportedly accessed using Lenovo identities, highlighting federated-identity and legacy-account risk. Heise
  • Microsoft warns that September Windows hotpatch updates may require an unexpected reboot. Heise
  1. Inventory and urgently patch HPE Fabric Composer, Team Password Manager and Elasticsearch.
  2. Patch Langflow; revoke OpenAI, AWS and other secrets accessible to affected instances.
  3. Validate Virtualizor updates using trusted sources and investigate BGP-related update anomalies.
  4. Hunt for Faronics Deploy abuse, unauthorized ScreenConnect installations and remote-admin persistence.
  5. Complete emergency remediation for JFrog Artifactory, PaperCut, SharePoint, Citrix and Gitea.
  6. Review CERT-Bund updates for GNU libc, Kemp LoadMaster and Exchange.
  7. Continue remediation of previously reported items: CVE-2026-53362, CVE-2023-49105, CVE-2026-19478, CVE-2019-1068, CVE-2026-77956 and CVE-2026-75759.