T
Threats
HPE Networking EdgeConnect SD-WAN Critical Vulnerabilities
Overview
CVEs: CVE-2026-76669, CVE-2026-76670, CVE-2026-76672, CVE-2026-76673, CVE-2026-76674, CVE-2026-76675
Severity: Critical
Date: 16 September 2026
HPE Networking has released updates for critical vulnerabilities in EdgeConnect SD-WAN Gateways and EdgeConnect SD-WAN Orchestrator. The highest CVSS v3.1 score is 9.9. HPE states it is not aware of public discussion or exploit code targeting these vulnerabilities as of the advisory release date, but strongly urges customers to patch because of their breadth and impact.
Affected Versions
HPE Networking EdgeConnect SD-WAN Gateways
Affected: ECOS 9.7.x.x 9.7.0.0 and below; ECOS 9.6.x.x 9.6.3.1 and below; ECOS 9.5.x.x 9.5.8.1 and below; ECOS 9.4.x.x 9.4.8.2 and below.
Fixed: ECOS 9.7.1.0 and above; ECOS 9.6.4.0 and above; ECOS 9.5.9.0 and above; ECOS 9.4.9.0 and above.
Not affected: Other HPE Networking products and software versions not specifically listed in the advisory.
HPE Networking EdgeConnect SD-WAN Orchestrator
Affected: Orchestrator 9.7.x 9.7.0 and below; Orchestrator 9.6.x 9.6.3 and below; Orchestrator 9.5.x 9.5.8 and below; Orchestrator 9.4.x 9.4.10 and below.
Fixed: Orchestrator 9.7.1 and above; Orchestrator 9.6.4 and above; Orchestrator 9.5.9 and above; Orchestrator 9.4.11 and above.
Not affected: Other HPE Networking products and software versions not specifically listed in the advisory.
HPE advises that the EdgeConnect SD-WAN Orchestrator version must be greater than or equal to the ECOS version operating on any EdgeConnect SD-WAN Gateway. Software releases past end of maintenance are presumed affected unless HPE explicitly states otherwise and are not covered by the advisory.
Vulnerability Breakdown
CVE-2026-76669 - Authorisation Bypass and Privilege Escalation
Severity: Critical
CVSS: 9.9
Description: An API vulnerability in EdgeConnect SD-WAN Orchestrator can allow a remote authenticated user with low privileges to escalate to administrative privileges.
Impact: Complete compromise of the Orchestrator.
Conditions: Remote access and a low-privileged authenticated account are required.
CVE-2026-76670 - Authorisation Bypass and Privilege Escalation
Severity: Critical
CVSS: 9.9
Description: An API vulnerability in EdgeConnect SD-WAN Orchestrator can allow a remote authenticated user with low privileges to escalate to administrative privileges.
Impact: Complete compromise of the Orchestrator.
Conditions: Remote access and a low-privileged authenticated account are required.
CVE-2026-76672 - Sensitive Information Disclosure
Severity: Critical
CVSS: 9.9
Description: A cache-synchronisation endpoint issue in EdgeConnect SD-WAN Orchestrator could expose sensitive configuration information.
Impact: Disclosure of third-party API tokens and credentials, potentially enabling lateral movement to external security platforms.
Conditions: Remote access and an authenticated read-only account are required.
CVE-2026-76673 - Authentication Bypass
Severity: Critical
CVSS: 9.8
Description: API vulnerabilities in EdgeConnect SD-WAN Orchestrator could allow a remote unauthenticated actor to bypass authentication controls.
Impact: Administrative access and complete compromise of the Orchestrator host.
Conditions: Remote network access is required. Authentication is not required.
CVE-2026-76674 - Buffer Overflow and Remote Code Execution
Severity: Critical
CVSS: 9.8
Description: Buffer overflow vulnerabilities in the underlying operating system of EdgeConnect SD-WAN Gateways could allow a remote unauthenticated attacker to execute arbitrary code.
Impact: Arbitrary command execution on the underlying operating system and complete system compromise.
Conditions: Remote network access is required. Authentication is not required.
CVE-2026-76675 - Command Injection and Privilege Escalation
Severity: Critical
CVSS: 9.1
Description: A command injection vulnerability in the EdgeConnect SD-WAN Gateway command-line interface could allow arbitrary command execution.
Impact: Complete system compromise through commands executed on the underlying operating system.
Conditions: Remote access and an authenticated account with high privileges are required.
Mitigation
Upgrade affected EdgeConnect SD-WAN Gateways and Orchestrator deployments to the relevant fixed release listed above.
Confirm that the Orchestrator version is greater than or equal to the ECOS version deployed on each Gateway.
Restrict CLI and web-based management interfaces to a dedicated Layer 2 segment or VLAN, and control access using Layer 3 or higher firewall policies.
Apply accounting controls to track and log user activity and resource usage.
Identify deployments on end-of-maintenance or end-of-support releases and move them to a supported release as a priority.
Summary for IT Teams
Products: HPE Networking EdgeConnect SD-WAN Gateways and EdgeConnect SD-WAN Orchestrator
Threat Level: Critical, up to CVSS 9.9
Action Required: Identify affected ECOS and Orchestrator versions, restrict management-plane exposure, and upgrade to the applicable fixed releases immediately.
References
Need Help?
Secure ISS can help assess exposure, validate upgrade paths, and implement management-plane access controls. Contact us on 1300 769 460.

