HPE Issues Urgent Security Patches for Critical SD-WAN Vulnerabilities, Urges Immediate Upgrade
September 16, 2026
Hewlett Packard Enterprise issued security updates for HPE EdgeConnect SD-WAN Gateways and SD-WAN Orchestrator after identifying multiple vulnerabilities that could allow remote attackers to fully compromise affected systems.
Critical flaws include CVE-2026-76669 and CVE-2026-76670 (API authorization bypass with privilege escalation) and CVE-2026-76672 (authenticated information disclosure of configuration data), all at CVSS 9.9, along with CVE-2026-76673 (API authentication bypass, CVSS 9.8) and CVE-2026-76674 (edge gateway buffer overflow, CVSS 9.8).
The advisory warns that exploitation could enable credential theft and lateral movement into connected security platforms, with vulnerabilities spanning command injection, buffer overflow, server-side request forgery, and denial-of-service across EdgeConnect and Orchestrator components.
The vulnerabilities are documented in Security Bulletin HPESBNW05135, dated September 15, 2026, noting edge-case impacts on management interfaces and APIs used by EdgeConnect deployments.
Affected are specific EdgeConnect ECOS releases up to certain older versions and Orchestrator releases up to certain older versions; fixed versions are ECOS 9.7.1.0, 9.6.4.0, 9.5.9.0, 9.4.9.0 or later, and Orchestrator 9.7.1, 9.6.4, 9.5.9, or 9.4.11 or later, with Orchestrator versions needing to be equal to or newer than the ECOS version on managed gateways.
HPE urges immediate upgrade and temporarily, isolating management interfaces on dedicated Layer 2 segments, enforcing Layer 3 firewall policies, and logging administrative activity; no public exploits had been reported at bulletin release.
An unauthenticated or low-privilege attacker could gain administrative access, execute arbitrary code, exfiltrate credentials, or disrupt/fully compromise Orchestrator hosts or gateways.
Summary based on 1 source
Get a daily email with more Tech stories
Source

CybersecurityNews • Sep 16, 2026
Critical HPE Vulnerabilities Allow Remote Attackers to Achieve Complete System Compromise