CVE-2026-76682: Unauthenticated Denial-of-Service Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways
Published Sep 15, 2026
·Updated
A vulnerability in the network security monitoring component of intrusion detection systems could allow an unauthenticated remote attacker to exploit a limited buffer overflow. Successful exploitation could allow an attacker to cause a denial-of-service or potentially execute arbitrary code on the system.
Affected Software
1 affected component
HPE EdgeConnect SD-WAN Gateways
Event History
Sep 15, 2026
CVE Published
via MITRE·07:23 PM
Data Sourced
via MITRE·07:23 PM
DescriptionSeverity
Frequently Asked Questions
1
Does exploitation require valid credentials or user interaction?
No. The issue can be exploited by an unauthenticated remote attacker and does not require user interaction.
2
Is arbitrary code execution confirmed as an outcome?
The available information confirms denial-of-service as a possible outcome. It states that arbitrary code execution may be possible, but does not confirm it.