CVE-2026-76679
moderateUnauthenticated Denial-of-Service in HPE Networking EdgeConnect SD-WAN Gateways
CVE-2026-76679 is a denial-of-service vulnerability in HPE Networking EdgeConnect SD-WAN Gateway appliances that can be triggered by an unauthenticated attacker with access to the network segment adjacent to the gateway (the CVSS vector also scores it as network-reachable with no privileges, no user interaction, and low complexity). Successful exploitation crashes the gateway, and critically, the device does not recover on its own — a manual intervention is required to bring it back up, prolonging the outage. This directly disrupts SD-WAN operations at the affected site, including branch-to-branch and branch-to-data-center connectivity for any organization relying on the gateway. All deployments of HPE Networking (formerly Aruba/Silver Peak) EdgeConnect SD-WAN Gateways described in the advisory are affected; no specific version range was provided in the available data, so defenders should consult the HPE bulletin. There is no known public proof-of-concept, the flaw is not on the CISA KEV list, and no exploitation in the wild has been reported as of this analysis.
What to do: Apply the patched firmware versions specified in the HPE Security Bulletin for EdgeConnect SD-WAN Gateways as soon as it is available, and prioritize gateways in untrusted or shared network segments. Mitigate by restricting which subnets and VLANs can reach the gateway's data-plane and management interfaces with ACLs and segmentation, since exploitation requires no authentication. Verify you have out-of-band or console access to each site so a crashed gateway can be manually recovered quickly, and monitor appliances for unexpected crashes or non-responsive edge devices.
| HPE (Hewlett Packard Enterprise) Networking EdgeConnect SD-WAN Gateway | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conduct denial-of-service attacks. Successful exploitation could allow an attacker to crash the system, preventing it from rebooting without manual intervention and disrupting network operations.
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.