ZeroHour

CVE-2026-76690

large

Authenticated Root RCE in HPE Networking EdgeConnect SD-WAN Gateway

CVSS 3.1
7.2 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-76690 is an arbitrary command execution flaw in a component of the HPE Networking EdgeConnect SD-WAN Gateway (formerly Aruba/Silver Peak EdgeConnect). A remote attacker who already possesses valid credentials can submit specially crafted input to the affected component, and successful exploitation results in remote code execution as root on the gateway appliance. Because it requires high privileges (PR:H per the CVSS 3.1 vector, scored 7.2), the primary risk is credential-compromised insiders, brute-forced or leaked admin accounts, or attackers chaining with an auth-bypass flaw. Organizations running EdgeConnect SD-WAN gateways at branch, data center, or cloud edge sites are affected. There is no known public proof of concept and no indication of exploitation in the wild; the CVE is not on the CISA KEV list.

What to do: Apply the patched firmware versions identified in HPE's security bulletin for EdgeConnect SD-WAN gateways as soon as releases are available. Since exploitation requires valid credentials, restrict management and orchestration interfaces to trusted admin networks or VPN, enforce strong unique credentials with MFA where supported, and rotate admin accounts. Review gateway audit logs for anomalous administrative sessions or unexpected command execution and validate that only expected accounts exist.

Affected
HPE (HPE Networking, formerly Aruba) EdgeConnect SD-WAN Gateway
Estimated exposure
largeplausibly tens of thousands of gateway appliances deployed at enterprise branch/edge sites (order of 10,000–100,000 devices) — EdgeConnect is a top-tier SD-WAN platform with thousands of enterprise customers (HPE acquired Silver Peak with a large install base in 2020), each typically operating multiple WAN-terminating gateways per deployment; exact…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability exists in a component of the HPE Networking EdgeConnect SD-WAN Gateways that may allow for arbitrary command execution. An authenticated remote attacker could exploit this vulnerability by providing a specially crafted input to the affected component. Successful exploitation could result in remote code execution as root.

Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.