CVE-2026-76682: Unauthenticated Denial-of-Service Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways
Published Sep 15, 2026
·Updated
A vulnerability in the network security monitoring component of intrusion detection systems could allow an unauthenticated remote attacker to exploit a limited buffer overflow. Successful exploitation could allow an attacker to cause a denial-of-service or potentially execute arbitrary code on the system.
Affected Software
9 affected components
HPE EdgeConnect SD-WAN Gateways
Arubanetworks Edgeconnect Sd-wan Orchestrator>=9.4.0<9.4.11
Arubanetworks Edgeconnect Sd-wan Orchestrator>=9.5.0<9.5.9
Arubanetworks Edgeconnect Sd-wan Orchestrator>=9.6.0<9.6.4
Arubanetworks Edgeconnect Sd-wan Orchestrator=9.7.0
HPE Edgeconnect Operating System>=9.4.0.0<9.4.9.0
HPE Edgeconnect Operating System>=9.5.0.0<9.5.9.0
HPE Edgeconnect Operating System>=9.6.0.0<9.6.4.0
HPE Edgeconnect Operating System=9.7.0.0
Event History
Sep 15, 2026
CVE Published
via MITRE·07:23 PM
Data Sourced
via MITRE·07:23 PM
DescriptionSeverity
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Does exploitation require valid credentials or user interaction?
No. The issue can be exploited by an unauthenticated remote attacker and does not require user interaction.
2
Is arbitrary code execution confirmed as an outcome?
The available information confirms denial-of-service as a possible outcome. It states that arbitrary code execution may be possible, but does not confirm it.