T

Threats

HPE Networking EdgeConnect SD-WAN Critical Vulnerabilities

Overview

HPE Networking has released updates for critical vulnerabilities in EdgeConnect SD-WAN Gateways and EdgeConnect SD-WAN Orchestrator. The highest CVSS v3.1 score is 9.9. HPE states it is not aware of public discussion or exploit code targeting these vulnerabilities as of the advisory release date, but strongly urges customers to patch because of their breadth and impact.


Affected Versions

HPE Networking EdgeConnect SD-WAN Gateways

  • Affected: ECOS 9.7.x.x 9.7.0.0 and below; ECOS 9.6.x.x 9.6.3.1 and below; ECOS 9.5.x.x 9.5.8.1 and below; ECOS 9.4.x.x 9.4.8.2 and below.

  • Fixed: ECOS 9.7.1.0 and above; ECOS 9.6.4.0 and above; ECOS 9.5.9.0 and above; ECOS 9.4.9.0 and above.

  • Not affected: Other HPE Networking products and software versions not specifically listed in the advisory.

  • Source: HPE Security Bulletin HPESBNW05135

HPE Networking EdgeConnect SD-WAN Orchestrator

  • Affected: Orchestrator 9.7.x 9.7.0 and below; Orchestrator 9.6.x 9.6.3 and below; Orchestrator 9.5.x 9.5.8 and below; Orchestrator 9.4.x 9.4.10 and below.

  • Fixed: Orchestrator 9.7.1 and above; Orchestrator 9.6.4 and above; Orchestrator 9.5.9 and above; Orchestrator 9.4.11 and above.

  • Not affected: Other HPE Networking products and software versions not specifically listed in the advisory.

  • Source: HPE Security Bulletin HPESBNW05135

HPE advises that the EdgeConnect SD-WAN Orchestrator version must be greater than or equal to the ECOS version operating on any EdgeConnect SD-WAN Gateway. Software releases past end of maintenance are presumed affected unless HPE explicitly states otherwise and are not covered by the advisory.


Vulnerability Breakdown

CVE-2026-76669 - Authorisation Bypass and Privilege Escalation

  • Severity: Critical

  • CVSS: 9.9

  • Description: An API vulnerability in EdgeConnect SD-WAN Orchestrator can allow a remote authenticated user with low privileges to escalate to administrative privileges.

  • Impact: Complete compromise of the Orchestrator.

  • Conditions: Remote access and a low-privileged authenticated account are required.

CVE-2026-76670 - Authorisation Bypass and Privilege Escalation

  • Severity: Critical

  • CVSS: 9.9

  • Description: An API vulnerability in EdgeConnect SD-WAN Orchestrator can allow a remote authenticated user with low privileges to escalate to administrative privileges.

  • Impact: Complete compromise of the Orchestrator.

  • Conditions: Remote access and a low-privileged authenticated account are required.

CVE-2026-76672 - Sensitive Information Disclosure

  • Severity: Critical

  • CVSS: 9.9

  • Description: A cache-synchronisation endpoint issue in EdgeConnect SD-WAN Orchestrator could expose sensitive configuration information.

  • Impact: Disclosure of third-party API tokens and credentials, potentially enabling lateral movement to external security platforms.

  • Conditions: Remote access and an authenticated read-only account are required.

CVE-2026-76673 - Authentication Bypass

  • Severity: Critical

  • CVSS: 9.8

  • Description: API vulnerabilities in EdgeConnect SD-WAN Orchestrator could allow a remote unauthenticated actor to bypass authentication controls.

  • Impact: Administrative access and complete compromise of the Orchestrator host.

  • Conditions: Remote network access is required. Authentication is not required.

CVE-2026-76674 - Buffer Overflow and Remote Code Execution

  • Severity: Critical

  • CVSS: 9.8

  • Description: Buffer overflow vulnerabilities in the underlying operating system of EdgeConnect SD-WAN Gateways could allow a remote unauthenticated attacker to execute arbitrary code.

  • Impact: Arbitrary command execution on the underlying operating system and complete system compromise.

  • Conditions: Remote network access is required. Authentication is not required.

CVE-2026-76675 - Command Injection and Privilege Escalation

  • Severity: Critical

  • CVSS: 9.1

  • Description: A command injection vulnerability in the EdgeConnect SD-WAN Gateway command-line interface could allow arbitrary command execution.

  • Impact: Complete system compromise through commands executed on the underlying operating system.

  • Conditions: Remote access and an authenticated account with high privileges are required.


Mitigation

  • Upgrade affected EdgeConnect SD-WAN Gateways and Orchestrator deployments to the relevant fixed release listed above.

  • Confirm that the Orchestrator version is greater than or equal to the ECOS version deployed on each Gateway.

  • Restrict CLI and web-based management interfaces to a dedicated Layer 2 segment or VLAN, and control access using Layer 3 or higher firewall policies.

  • Apply accounting controls to track and log user activity and resource usage.

  • Identify deployments on end-of-maintenance or end-of-support releases and move them to a supported release as a priority.


Summary for IT Teams

  • Products: HPE Networking EdgeConnect SD-WAN Gateways and EdgeConnect SD-WAN Orchestrator

  • Threat Level: Critical, up to CVSS 9.9

  • Action Required: Identify affected ECOS and Orchestrator versions, restrict management-plane exposure, and upgrade to the applicable fixed releases immediately.


References


Need Help?

Secure ISS can help assess exposure, validate upgrade paths, and implement management-plane access controls. Contact us on 1300 769 460.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.