CVE-2026-76690
largeAuthenticated Root RCE in HPE Networking EdgeConnect SD-WAN Gateway
CVE-2026-76690 is an arbitrary command execution flaw in a component of the HPE Networking EdgeConnect SD-WAN Gateway (formerly Aruba/Silver Peak EdgeConnect). A remote attacker who already possesses valid credentials can submit specially crafted input to the affected component, and successful exploitation results in remote code execution as root on the gateway appliance. Because it requires high privileges (PR:H per the CVSS 3.1 vector, scored 7.2), the primary risk is credential-compromised insiders, brute-forced or leaked admin accounts, or attackers chaining with an auth-bypass flaw. Organizations running EdgeConnect SD-WAN gateways at branch, data center, or cloud edge sites are affected. There is no known public proof of concept and no indication of exploitation in the wild; the CVE is not on the CISA KEV list.
What to do: Apply the patched firmware versions identified in HPE's security bulletin for EdgeConnect SD-WAN gateways as soon as releases are available. Since exploitation requires valid credentials, restrict management and orchestration interfaces to trusted admin networks or VPN, enforce strong unique credentials with MFA where supported, and rotate admin accounts. Review gateway audit logs for anomalous administrative sessions or unexpected command execution and validate that only expected accounts exist.
| HPE (HPE Networking, formerly Aruba) EdgeConnect SD-WAN Gateway | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability exists in a component of the HPE Networking EdgeConnect SD-WAN Gateways that may allow for arbitrary command execution. An authenticated remote attacker could exploit this vulnerability by providing a specially crafted input to the affected component. Successful exploitation could result in remote code execution as root.
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.