CVE-2026-76674
moderateUnauthenticated Buffer Overflow RCE in HPE EdgeConnect SD-WAN Gateways
CVE-2026-76674 is a critical (CVSS 9.8) buffer overflow vulnerability in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways (EdgeConnect OS/ECOS appliances). It is triggered remotely over the network with no authentication, no privileges, and no user interaction required, and successful exploitation allows an attacker to execute arbitrary commands on the gateway's OS, leading to complete system compromise of the appliance. Affected parties are enterprises and service providers operating HPE EdgeConnect SD-WAN branch or data-center gateways, especially any with management or data-plane services reachable from untrusted networks. Because gateways sit at the network edge, compromise can enable traffic interception or pivoting into internal corporate networks. No public proof of concept is known and the flaw is not in CISA's KEV catalog, so no active exploitation has been reported to date.
What to do: Apply the patched EdgeConnect OS release specified in HPE's security bulletin to all affected gateways as soon as it is available (the exact fixed version must be taken from the HPE advisory, as it is not stated here). In the interim, restrict gateway management and service ports to trusted orchestrator/admin networks using firewall rules or ACLs, and run external scans to confirm none of your gateways are internet-reachable. Monitor gateway logs, the HPE advisory, and the CISA KEV catalog for signs of exploitation.
| Hewlett Packard Enterprise (HPE) HPE Networking EdgeConnect SD-WAN Gateway (EdgeConnect OS / ECOS) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to execute arbitrary code. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.