CVE-2026-76692: Unauthenticated Adjacent Information Disclosure and Denial-of-Service Vulnerability in HPE Networking EdgeConnect SD-WAN Gateways
Published Sep 15, 2026
·Updated
A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to obtain limited information from memory and disrupt the normal operation of the affected service. Successful exploitation could result in a denial of service (system crash) or the disclosure of uninitialized stack memory.
Affected Software
9 affected components
HPE Networking EdgeConnect SD-WAN Gateways
Arubanetworks Edgeconnect Sd-wan Orchestrator>=9.4.0<9.4.11
Arubanetworks Edgeconnect Sd-wan Orchestrator>=9.5.0<9.5.9
Arubanetworks Edgeconnect Sd-wan Orchestrator>=9.6.0<9.6.4
Arubanetworks Edgeconnect Sd-wan Orchestrator=9.7.0
HPE Edgeconnect Operating System>=9.4.0.0<9.4.9.0
HPE Edgeconnect Operating System>=9.5.0.0<9.5.9.0
HPE Edgeconnect Operating System>=9.6.0.0<9.6.4.0
HPE Edgeconnect Operating System=9.7.0.0
Event History
Sep 15, 2026
CVE Published
via MITRE·07:23 PM
Data Sourced
via MITRE·07:23 PM
DescriptionSeverity
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attacker must be adjacent to the affected gateway. Exploitation does not require authentication or user interaction.