CVE-2026-76686
moderateUnauthenticated Remote DoS in HPE EdgeConnect SD-WAN Gateway OS
CVE-2026-76686 is a denial-of-service vulnerability in the underlying operating system (ECOS) of HPE Networking EdgeConnect SD-WAN Gateways. An unauthenticated remote attacker can trigger the flaw by sending crafted traffic to the affected service over the network with no privileges or user interaction required, causing the service to crash or become unavailable. Successful exploitation impacts availability only (CVSS 3.1: 7.5, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) — there is no confidentiality or integrity impact — but it can disrupt SD-WAN traffic for all sites that rely on the affected gateway. Organizations running EdgeConnect SD-WAN Gateways, which are typically internet-facing by design for SD-WAN overlay termination, are the affected population. No public proof-of-concept is known and the flaw is not listed in CISA's KEV catalog, so exploitation appears limited to none at this time.
What to do: Review the HPE security advisory for the list of affected ECOS versions and upgrade affected EdgeConnect SD-WAN Gateways to the fixed release as soon as it is available. Until patched, restrict which interfaces and source addresses can reach the affected service on gateway devices and verify high-availability/failover configuration so a single gateway outage does not sever branch connectivity. Monitor gateway availability and crash logs for unexpected restarts that could indicate exploitation attempts.
| HPE (Hewlett Packard Enterprise) HPE Networking EdgeConnect SD-WAN Gateway | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability exists in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an unauthenticated remote attacker to conduct a denial-of-service attack on the affected service.
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.