HPE published 81 CVE records for AOS-CX and Fabric Composer inside one hour on September 1, and every one of them names the last affected version rather than the fixed one.
What happened
At 8:17 p.m. UTC on Tuesday, September 1, 2026, the National Vulnerability Database ingested 52 CVE records assigned by [email protected] for HPE Networking Fabric Composer. An hour later, at 9:18 p.m. UTC, it ingested 29 more for AOS-CX, the operating system on HPE Aruba Networking’s campus switch lines. All 81 records point at exactly two documents: HPE bulletin HPESBNW05133 for Fabric Composer and HPESBNW05134 for AOS-CX.
The highest-scored record in the switch batch is CVE-2026-73749, which HPE scores 9.8 critical on CVSS 3.1 with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Its description reads, in full: “Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service. Successful exploitation could result in remote code execution with elevated privileges.”
Note the plural. One CVE ID is carrying an unspecified number of separate defects in an unnamed daemon.
The rest of the switch batch is not filler. CVE-2026-73752 is an unauthenticated arbitrary file write in an AOS-CX API endpoint at 8.8. CVE-2026-73782 is a format string flaw in the command line interface, also 8.8. CVE-2026-73777 (8.1) and CVE-2026-73779 (8.2) are both described as allowing “an unauthenticated remote actor to bypass authentication controls,” one in an API endpoint and one in the operating system. CVE-2026-73776 (7.9) is a signature verification bypass in the CLI. CVE-2026-73773 (7.5) is an unauthenticated denial of service against an API endpoint.
On the Fabric Composer side, CVE-2026-19766 carries a 9.6 with the vector AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. HPE’s text: “An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated adjacent attacker to execute arbitrary code as a privileged user on the underlying operating system, leading to complete compromise of the AFC host.” Two more sit at 9.0 — a stored cross-site scripting flaw reachable by a low-privilege operator against administrative users, and an unauthenticated remote code execution in the underlying operating system that HPE qualifies as requiring “certain preconditions.”
Every AOS-CX record in the batch carries the identical affected range: 10.18.0000 through 10.18.0001, 10.17.0000 through 10.17.1021, 10.16.0000 through 10.16.1051, 10.13.0000 through 10.13.1180, and 10.10.0000 through 10.10.1180. Every Fabric Composer record carries 7.0.0 through 7.3.3.
Those are ceilings, not remedies. NVD’s versionEndIncluding field states the highest build known to be vulnerable. It does not assert that the next build is fixed, and nothing in any of the 81 records names a target version.
The bulletins do — presumably. Neither renders. Requests to support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us and to the cdn.support.hpe.com mirror return a document whose body contains a viewport meta tag and nothing else; the advisory text is assembled client-side. A human with a browser gets the fixed versions. A scanner, a scheduled job, or a vulnerability-management pipeline gets an empty page.
No source consulted claims exploitation. None of the 81 records carries cisaExploitAdd or cisaActionDue, so there is no federal remediation clock on any of them as of this writing.
Why it matters
The gap between “a fix exists” and “the record says which build contains it” is the most reliably recurring failure this publication tracks, and it usually shows up one CVE at a time. Eighty-one at once, from a first-party CNA writing about its own products, is a different scale of the same problem.
It matters more here because of what the affected version ranges say when you line them up against the last AOS-CX advisory. In March 2026, HPE fixed a separate set of AOS-CX flaws including a 9.8 authentication bypass; Singapore’s Cyber Security Agency, republishing that advisory on March 12, listed the affected builds as 10.17.0001 and below, 10.16.1020 and below, 10.13.1160 and below, and 10.10.1170 and below. The new batch’s affected ranges run to 10.17.1021, 10.16.1051, 10.13.1180, and 10.10.1180 — past all four of those. An operator who patched in March, correctly and on time, is inside every one of the 29 new records. That is not a criticism of HPE; new code carries new defects. It is a warning against reading “we already patched Aruba this year” as coverage.
The single-ID-for-multiple-defects construction in CVE-2026-73749 compounds it. If an unnamed daemon has several input-handling bugs behind one identifier, an operator cannot reason about partial remediation, and a future KEV listing for that ID would not say which of the bundled defects is the one being exploited. The same shape appears throughout the batch: “vulnerabilities exist,” plural, under a single record, at least eight times across the 29.
Then there is the machine-readability problem, which is now a policy problem as well as an operational one. BOD 26-04 derives federal remediation deadlines from four binary variables — internet exposure, KEV listing, exploit automation, and total versus partial technical impact — and the shortest band is three days, some of it carrying an additional forensic triage obligation. A three-day clock assumes an agency can determine the target build quickly. If CVE-2026-73749 were added to the KEV catalog tomorrow, the authoritative statement of what to upgrade to would live in a JavaScript-rendered support page that no automated inventory tool can read. This publication has already reported that BOD 26-04’s own deadline schedule is published only as PNG images in Appendix A with no alt text, and that vendors transcribing it by eye disagree with one another. A directive whose schedule is an unreadable image, applied to advisories whose remediation is an unreadable page, is not a workable pipeline.
Scoring is worth one note. On all 81 records the only CVSS present is HPE’s own, typed Secondary; NVD has not performed its primary analysis, and the records carry no CWE. That is normal for records this fresh and it is not a criticism — but it means every number quoted here is the vendor’s self-assessment of its own product, and it will be worth rechecking these scores after NVD analysis lands.
Finally, the assets. AOS-CX runs the switch control plane; Fabric Composer is the controller that programs a data center fabric, which is why HPE’s own text for the 9.6 reaches for the phrase “complete compromise of the AFC host.” That one is scored adjacent rather than network — AV:A — meaning it needs a foothold on the same layer-two segment. For most deployments, that segment is the management VLAN, which makes the management VLAN the control that matters most tonight.
What to do
Inventory by version first. If your AOS-CX estate is anywhere in 10.10.x, 10.13.x, 10.16.x, 10.17.x, or 10.18.0000 to 10.18.0001, assume you are inside all 29 records until you have confirmed otherwise against the bulletin. Fabric Composer 7.0.0 through 7.3.3 is likewise inside all 52.
Get the fixed versions from HPESBNW05134 (AOS-CX) and HPESBNW05133 (Fabric Composer) on support.hpe.com, opened in a real browser. Do not expect your scanner or a scripted fetch to retrieve them; it will get an empty document and may silently record no result. If you patched AOS-CX in March, check anyway — 10.10.1180 and 10.13.1180 are both inside the new affected ranges.
Until you have upgraded, treat the management plane as the mitigation. The 9.8 is described only as “specially crafted packets to the affected service,” with the daemon unnamed, so there is no port to filter with confidence — segmentation and access control on switch management interfaces, the REST API, and the web UI are what remain. Several of the high-scoring records in both batches are reachable through the API or the web interface specifically. For Fabric Composer, the adjacent-only 9.6 makes the AFC management segment a trust boundary that should not contain untrusted hosts.
There is no evidence of exploitation and no federal deadline. This is a plan-your-maintenance-window item, not a tonight item — but it is a large one, and the version research will take longer than it should.
Sourcing note
Checked: the NVD 2.0 API for all CVEs published between 7:00 p.m. UTC on September 1 and 2:00 a.m. UTC on September 2, which returned the two HPE batches (52 Fabric Composer records at 8:17 p.m. UTC, 29 AOS-CX records at 9:18 p.m. UTC); the individual NVD records for CVE-2026-73749 and CVE-2026-19766, including full CVSS vectors, affected-version configurations, and reference lists; and NVD’s KEV fields, which are absent on all 81. All descriptions and scores quoted above are HPE’s, as published through NVD.
Could not reach: HPE bulletins HPESBNW05133 and HPESBNW05134. Both support.hpe.com and cdn.support.hpe.com returned a document containing only a viewport meta tag, with the advisory body rendered client-side. That failure is itself reported above rather than routed around; the fixed version numbers in this story are therefore absent, not omitted.
Cross-checked: the Cyber Security Agency of Singapore’s alert AL-2026-023, dated March 12, 2026, for the affected-version ceilings of the previous AOS-CX advisory. The Canadian Centre for Cyber Security’s most recent HPE advisory, AV26-727, is dated July 22, 2026 and does not cover this release.
Unresolved: the fixed AOS-CX and Fabric Composer builds; the identity of the daemon in CVE-2026-73749 and how many distinct defects that single record covers; whether NVD’s primary analysis will agree with HPE’s scores; and whether CISA will mirror either bulletin. Related coverage on this site: a KEV entry whose CVE record still says no fixed version exists, a record naming a fixed version that does not contain the fix, and BOD 26-04’s deadline schedule published only as images.
