Back Secure-Iss HPE Networking EdgeConnect SD-WAN Critical Vulnerabilities
CVEs: CVE-2026-76669 , CVE-2026-76670 , CVE-2026-76672 , CVE-2026-76673 , CVE-2026-76674 , CVE-2026-76675
CVEs: CVE-2026-76669 , CVE-2026-76670 , CVE-2026-76672 , CVE-2026-76673 , CVE-2026-76674 , CVE-2026-76675
Date: 16 September 2026
Date: 16 September 2026
HPE Networking has released updates for critical vulnerabilities in EdgeConnect SD-WAN Gateways and EdgeConnect SD-WAN Orchestrator. The highest CVSS v3.1 score is 9.9. HPE states it is not aware of public discussion or exploit code targeting these vulnerabilities as of the advisory release date, but strongly urges customers to patch because of their breadth and impact.
HPE Networking EdgeConnect SD-WAN Gateways
Affected: ECOS 9.7.x.x 9.7.0.0 and below; ECOS 9.6.x.x 9.6.3.1 and below; ECOS 9.5.x.x 9.5.8.1 and below; ECOS 9.4.x.x 9.4.8.2 and below.
Affected: ECOS 9.7.x.x 9.7.0.0 and below; ECOS 9.6.x.x 9.6.3.1 and below; ECOS 9.5.x.x 9.5.8.1 and below; ECOS 9.4.x.x 9.4.8.2 and below.
Fixed: ECOS 9.7.1.0 and above; ECOS 9.6.4.0 and above; ECOS 9.5.9.0 and above; ECOS 9.4.9.0 and above.
Fixed: ECOS 9.7.1.0 and above; ECOS 9.6.4.0 and above; ECOS 9.5.9.0 and above; ECOS 9.4.9.0 and above.
Not affected: Other HPE Networking products and software versions not specifically listed in the advisory.
Not affected: Other HPE Networking products and software versions not specifically listed in the advisory.
Source: HPE Security Bulletin HPESBNW05135
Source: HPE Security Bulletin HPESBNW05135
HPE Networking EdgeConnect SD-WAN Orchestrator
Affected: Orchestrator 9.7.x 9.7.0 and below; Orchestrator 9.6.x 9.6.3 and below; Orchestrator 9.5.x 9.5.8 and below; Orchestrator 9.4.x 9.4.10 and below.
Affected: Orchestrator 9.7.x 9.7.0 and below; Orchestrator 9.6.x 9.6.3 and below; Orchestrator 9.5.x 9.5.8 and below; Orchestrator 9.4.x 9.4.10 and below.
Fixed: Orchestrator 9.7.1 and above; Orchestrator 9.6.4 and above; Orchestrator 9.5.9 and above; Orchestrator 9.4.11 and above.
Fixed: Orchestrator 9.7.1 and above; Orchestrator 9.6.4 and above; Orchestrator 9.5.9 and above; Orchestrator 9.4.11 and above.
Not affected: Other HPE Networking products and software versions not specifically listed in the advisory.
Not affected: Other HPE Networking products and software versions not specifically listed in the advisory.
Source: HPE Security Bulletin HPESBNW05135
Source: HPE Security Bulletin HPESBNW05135
HPE advises that the EdgeConnect SD-WAN Orchestrator version must be greater than or equal to the ECOS version operating on any EdgeConnect SD-WAN Gateway. Software releases past end of maintenance are presumed affected unless HPE explicitly states otherwise and are not covered by the advisory.
Vulnerability Breakdown
CVE-2026-76669 - Authorisation Bypass and Privilege Escalation
Description: An API vulnerability in EdgeConnect SD-WAN Orchestrator can allow a remote authenticated user with low privileges to escalate to administrative privileges.
Description: An API vulnerability in EdgeConnect SD-WAN Orchestrator can allow a remote authenticated user with low privileges to escalate to administrative privileges.
Impact: Complete compromise of the Orchestrator.
Impact: Complete compromise of the Orchestrator.
Conditions: Remote access and a low-privileged authenticated account are required.
Conditions: Remote access and a low-privileged authenticated account are required.
CVE-2026-76670 - Authorisation Bypass and Privilege Escalation
Description: An API vulnerability in EdgeConnect SD-WAN Orchestrator can allow a remote authenticated user with low privileges to escalate to administrative privileges.
Description: An API vulnerability in EdgeConnect SD-WAN Orchestrator can allow a remote authenticated user with low privileges to escalate to administrative privileges.
Impact: Complete compromise of the Orchestrator.
Impact: Complete compromise of the Orchestrator.
Conditions: Remote access and a low-privileged authenticated account are required.
Conditions: Remote access and a low-privileged authenticated account are required.
CVE-2026-76672 - Sensitive Information Disclosure
Description: A cache-synchronisation endpoint issue in EdgeConnect SD-WAN Orchestrator could expose sensitive configuration information.
Description: A cache-synchronisation endpoint issue in EdgeConnect SD-WAN Orchestrator could expose sensitive configuration information.
Impact: Disclosure of third-party API tokens and credentials, potentially enabling lateral movement to external security platforms.
Impact: Disclosure of third-party API tokens and credentials, potentially enabling lateral movement to external security platforms.
Conditions: Remote access and an authenticated read-only account are required.
Conditions: Remote access and an authenticated read-only account are required.
CVE-2026-76673 - Authentication Bypass
Description: API vulnerabilities in EdgeConnect SD-WAN Orchestrator could allow a remote unauthenticated actor to bypass authentication controls.
Description: API vulnerabilities in EdgeConnect SD-WAN Orchestrator could allow a remote unauthenticated actor to bypass authentication controls.
Impact: Administrative access and complete compromise of the Orchestrator host.
Impact: Administrative access and complete compromise of the Orchestrator host.
Conditions: Remote network access is required. Authentication is not required.
Conditions: Remote network access is required. Authentication is not required.
CVE-2026-76674 - Buffer Overflow and Remote Code Execution
Description: Buffer overflow vulnerabilities in the underlying operating system of EdgeConnect SD-WAN Gateways could allow a remote unauthenticated attacker to execute arbitrary code.
Description: Buffer overflow vulnerabilities in the underlying operating system of EdgeConnect SD-WAN Gateways could allow a remote unauthenticated attacker to execute arbitrary code.
Impact: Arbitrary command execution on the underlying operating system and complete system compromise.
Impact: Arbitrary command execution on the underlying operating system and complete system compromise.
Conditions: Remote network access is required. Authentication is not required.
Conditions: Remote network access is required. Authentication is not required.
CVE-2026-76675 - Command Injection and Privilege Escalation
Description: A command injection vulnerability in the EdgeConnect SD-WAN Gateway command-line interface could allow arbitrary command execution.
Description: A command injection vulnerability in the EdgeConnect SD-WAN Gateway command-line interface could allow arbitrary command execution.
Impact: Complete system compromise through commands executed on the underlying operating system.
Impact: Complete system compromise through commands executed on the underlying operating system.
Conditions: Remote access and an authenticated account with high privileges are required.
Conditions: Remote access and an authenticated account with high privileges are required.
Upgrade affected EdgeConnect SD-WAN Gateways and Orchestrator deployments to the relevant fixed release listed above.
Upgrade affected EdgeConnect SD-WAN Gateways and Orchestrator deployments to the relevant fixed release listed above.
Confirm that the Orchestrator version is greater than or equal to the ECOS version deployed on each Gateway.
Confirm that the Orchestrator version is greater than or equal to the ECOS version deployed on each Gateway.
Restrict CLI and web-based management interfaces to a dedicated Layer 2 segment or VLAN, and control access using Layer 3 or higher firewall policies.
Restrict CLI and web-based management interfaces to a dedicated Layer 2 segment or VLAN, and control access using Layer 3 or higher firewall policies.
Apply accounting controls to track and log user activity and resource usage.
Apply accounting controls to track and log user activity and resource usage.
Identify deployments on end-of-maintenance or end-of-support releases and move them to a supported release as a priority.
Identify deployments on end-of-maintenance or end-of-support releases and move them to a supported release as a priority.
Products: HPE Networking EdgeConnect SD-WAN Gateways and EdgeConnect SD-WAN Orchestrator
Products: HPE Networking EdgeConnect SD-WAN Gateways and EdgeConnect SD-WAN Orchestrator
Threat Level: Critical, up to CVSS 9.9
Threat Level: Critical, up to CVSS 9.9
Action Required: Identify affected ECOS and Orchestrator versions, restrict management-plane exposure, and upgrade to the applicable fixed releases immediately.
Action Required: Identify affected ECOS and Orchestrator versions, restrict management-plane exposure, and upgrade to the applicable fixed releases immediately.
HPE Security Bulletin HPESBNW05135 - Multiple Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways and Orchestrator
HPE Security Bulletin HPESBNW05135 - Multiple Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways and Orchestrator
HPE CSAF Advisory for HPESBNW05135
HPE CSAF Advisory for HPESBNW05135
Secure ISS can help assess exposure, validate upgrade paths, and implement management-plane access controls. us on 1300 769 460.
Australia is secure when Australian talent defends it.
Reach out today to how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.
Australia is secure when Australian talent defends it.
Reach out today to how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.
Australia is secure when Australian talent defends it.
Reach out today to how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
