CVE-2026-76702: Authenticated Local Denial-of-Service Vulnerability in HPE Networking EdgeConnect SD-WAN Gateways
Published Sep 15, 2026
·Updated
A vulnerability in the operating system of HPE Networking EdgeConnect SD-WAN Gateways could allow an authenticated local attacker to cause a denial-of-service. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an unstable system state.
Affected Software
9 affected components
HPE Networking EdgeConnect SD-WAN Gateways
Arubanetworks Edgeconnect Sd-wan Orchestrator>=9.4.0<9.4.11
Arubanetworks Edgeconnect Sd-wan Orchestrator>=9.5.0<9.5.9
Arubanetworks Edgeconnect Sd-wan Orchestrator>=9.6.0<9.6.4
Arubanetworks Edgeconnect Sd-wan Orchestrator=9.7.0
HPE Edgeconnect Operating System>=9.4.0.0<9.4.9.0
HPE Edgeconnect Operating System>=9.5.0.0<9.5.9.0
HPE Edgeconnect Operating System>=9.6.0.0<9.6.4.0
HPE Edgeconnect Operating System=9.7.0.0
Event History
Sep 15, 2026
CVE Published
via MITRE·07:23 PM
Data Sourced
via MITRE·07:23 PM
DescriptionSeverity
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Who is realistically exposed to this issue?
HPE Networking EdgeConnect SD-WAN Gateways are affected. Exploitation is limited to attackers with authenticated local access, so systems without such access are not exposed through the attack vector described.
2
What access does an attacker need to exploit it?
An attacker needs local access and valid authentication with low privileges. No user interaction is required.
3
What is the operational impact if exploitation succeeds?
Successful exploitation can cause a denial of service, disrupt system operations, and potentially leave the gateway in an unstable state.