29 Total CVEs
29 AI Analyzed
1 CISA KEV
9 Critical

Profile

3.4% ended up actively exploited 1 of 29 added to CISA KEV
31% rated critical (CVSS 9.0+) 9 critical, 20 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

23 CVEs in the last 12 months

Products

  • Fabric Composer10
  • AOS-CX8
  • EdgeConnect SD-WAN Orchestrator2

3 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-29 of 29 CVEs
CVE-2026-76658
Analyzed
10
HPE Fabric Composer

A critical vulnerability in the HPE Fabric Composer SSH daemon allows unauthenticated remote attackers to achieve full administrative system compromis...

2026-09-02
CVE-2026-76657
Analyzed
10
HPE Fabric Composer

An authentication bypass vulnerability in the HPE Fabric Composer API allows unauthenticated remote attackers to gain administrative privileges and fu...

2026-09-02
CVE-2026-73782
Analyzed
8.8
HPE AOS-CX

A format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticated remote code execution. Successful expl...

2026-09-02
CVE-2026-73781
Analyzed
8.4
HPE AOS-CX

A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a stored cross-site scripting...

2026-09-02
CVE-2026-73780
Analyzed
8.3
HPE AOS-CX

A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Request Forgery (CSRF) protecti...

2026-09-02
CVE-2026-73753
Analyzed
8.8
HPE AOS-CX

Exploitation through affected command-line operations could allow an authenticated low-privileged user to execute arbitrary commands as a privileged u...

2026-09-02
CVE-2026-73752
Analyzed
8.8
HPE AOS-CX

An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. Successful exploitation of this vulnerability allows an att...

2026-09-02
CVE-2026-73751
Analyzed
8.8
HPE AOS-CX

An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands o...

2026-09-02
CVE-2026-73750
Analyzed
8.8
HPE AOS-CX

Vulnerabilities exist in the authentication module that may improperly process malformed or truncated input. An authenticated remote attacker could ex...

2026-09-02
CVE-2026-73749
Analyzed
9.8
HPE AOS-CX

AOS-CX contains multiple vulnerabilities in a daemon that allow an unauthenticated remote attacker to achieve remote code execution via specially craf...

2026-09-02
CVE-2026-73709
Analyzed
8.3
HPE Fabric Composer

A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an unauthenticated adjacent attacker to run arbitrary...

2026-09-02
CVE-2026-73708
Analyzed
8.3
HPE Fabric Composer

A business logic vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege...

2026-09-02
CVE-2026-73707
Analyzed
8.5
HPE Fabric Composer

Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low priv...

2026-09-02
CVE-2026-73705
Analyzed
8.8
HPE Fabric Composer

An arbitrary file write vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to escalat...

2026-09-02
CVE-2026-73704
Analyzed
8.8
HPE Fabric Composer

A command sanitization bypass exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege...

2026-09-02
CVE-2026-73703
Analyzed
8.8
HPE Fabric Composer

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated adjacent attacker to conduct a...

2026-09-02
CVE-2026-73702
Analyzed
8.8
HPE Fabric Composer

A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low pri...

2026-09-02
CVE-2026-63456
Analyzed
9.8
HPE EdgeConnect SD-WAN Orchestrator

Multiple vulnerabilities in the HPE EdgeConnect SD-WAN Orchestrator REST API allow unauthenticated remote attackers to bypass authentication and modif...

2026-08-05
CVE-2026-63455
Analyzed
9.8
HPE EdgeConnect SD-WAN Orchestrator

HPE EdgeConnect SD-WAN Orchestrator contains multiple REST API vulnerabilities that allow unauthenticated remote attackers to bypass authentication an...

2026-08-05
CVE-2026-23593
Analyzed
7.5
HPE Multiple Products

A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could allow an unauthenticated remote attacker to view s...

2026-01-28
CVE-2026-19766
Analyzed
9.6
HPE Fabric Composer

An authentication bypass vulnerability in HPE Fabric Composer allows unauthenticated adjacent attackers to execute arbitrary code with privileged acce...

2026-09-02
CVE-2025-37164
KEV Analyzed
10
HPE Multiple Products

A remote code execution issue exists in HPE OneView.

2025-12-17
CVE-2025-37163
Analyzed
7.2
HPE Multiple Products

A command injection vulnerability has been identified in the command line interface of the HPE Aruba Networking Airwave Platform

2025-11-19
CVE-2025-37125
Analyzed
7.5
HPE Multiple Products

A broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS)

2025-09-16
CVE-2025-37104
Analyzed
7.1
HPE Multiple Products

A security vulnerability has been identified in HPE Telco Service Orchestrator software

2025-07-16
CVE-2025-37103
Analyzed
9.8
HPE Multiple Products

Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal device aut...

2025-07-08
CVE-2025-37099
Analyzed
9.8
HPE Multiple Products

A remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.

2025-07-06
CVE-2025-37098
Analyzed
7.5
HPE Multiple Products

A path traversal vulnerability exists in HPE Insight Remote Support (IRS) prior to v7

2025-07-06
CVE-2025-37097
Analyzed
7.5
HPE Multiple Products

A vulnerability in HPE Insight Remote Support (IRS) prior to v7

2025-07-06