Critical Vulnerabilities in HPE Aruba Networking EdgeConnect SD
HPE Aruba Networking EdgeConnect SD-WAN Orchestrator, versions 9.4.0 through 9.7.0 (CVE-2026-76673)
HPE Aruba Networking EdgeConnect SD-WAN Gateways, underlying operating system, affected version range not stated in available source data (CVE-2026-76674)
CWE-287: Improper Authentication
CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CVE-2026-76673: CVSS 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVE-2026-76674: CVSS 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
HP -
HPE Aruba Networking EdgeConnect SD-WAN is a network platform used by organizations to manage and secure wide area network (WAN) connectivity across sites, combining centralized orchestration with gateway devices deployed at branch and data center locations.
If exploited, CVE-2026-76673 could allow an unauthenticated remote attacker to bypass authentication controls on the Orchestrator API and gain administrative privileges, resulting in complete compromise of the Orchestrator host. CVE-2026-76674 could allow an unauthenticated remote attacker to execute arbitrary code on the underlying operating system of EdgeConnect Gateways, resulting in complete compromise of the gateway.
In both cases, successful exploitation could allow attackers to access and exfiltrate sensitive network configuration and routing data (Confidentiality), alter WAN policies, routing behavior, or gateway configuration (Integrity), and disrupt or fully take down WAN connectivity for affected sites (Availability).
CVE-2026-76673 is an authentication bypass vulnerability in the API of the EdgeConnect SD-WAN Orchestrator. An unauthenticated remote attacker can send crafted API requests that circumvent existing authentication controls, granting administrative privileges on the Orchestrator without valid credentials. No user interaction is required and no privileges are needed to exploit the flaw.
CVE-2026-76674 consists of buffer overflow vulnerabilities in the underlying operating system of EdgeConnect SD-WAN Gateways. An unauthenticated remote attacker can trigger the overflow to execute arbitrary code on the underlying OS, leading to complete system compromise of the gateway. No user interaction or prior authentication is required.
The Centre for Cybersecurity Belgium strongly recommends installing updates for vulnerable devices with the highest priority after thorough testing.
The CCB recommends organizations upscale monitoring and detection capabilities to identify any related suspicious activity and ensure a swift response in case of an intrusion.
In case of an intrusion, you can report an incident via . While patching appliances or software to the newest version may protect against future exploitation, it does not remediate historic compromise.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
