CVE-2026-76674: Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking EdgeConnect SD-WAN Gateways
Published Sep 15, 2026
·Updated
Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to execute arbitrary code. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.
Affected Software
9 affected components
HPE Networking EdgeConnect SD-WAN Gateways
Arubanetworks Edgeconnect Sd-wan Orchestrator>=9.4.0<9.4.11
Arubanetworks Edgeconnect Sd-wan Orchestrator>=9.5.0<9.5.9
Arubanetworks Edgeconnect Sd-wan Orchestrator>=9.6.0<9.6.4
Arubanetworks Edgeconnect Sd-wan Orchestrator=9.7.0
HPE Edgeconnect Operating System>=9.4.0.0<9.4.9.0
HPE Edgeconnect Operating System>=9.5.0.0<9.5.9.0
HPE Edgeconnect Operating System>=9.6.0.0<9.6.4.0
HPE Edgeconnect Operating System=9.7.0.0
Event History
Sep 15, 2026
CVE Published
via MITRE·07:23 PM
Data Sourced
via MITRE·07:23 PM
DescriptionSeverity
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Who can exploit this issue?
An unauthenticated remote attacker can exploit it; no prior authentication or user interaction is required.
2
What level of access could successful exploitation provide?
Successful exploitation could allow arbitrary code and command execution on the underlying operating system, resulting in complete compromise of the affected gateway.