Authenticated Secret Disclosure in HPE SD-WAN Orchestrator Cache Sync Endpoint
CVE-2026-76672 is a critical (CVSS 9.9) information disclosure flaw in HPE's SD-WAN Orchestrator affecting the cache synchronization endpoint. An authenticated remote attacker holding only read-only privileges can send a specially crafted request to that endpoint, which returns sensitive configuration data without further authorization checks. Successful exploitation discloses third-party API tokens and credentials, which could enable lateral movement into external security platforms integrated with the orchestrator. The vulnerability affects HPE SD-WAN Orchestrator deployments exposed to authenticated users; no specific version ranges were provided in the advisory data. There is no known public proof of concept and the flaw is not on CISA's KEV list, so exploitation status is currently none known.
· HPE SD-WAN Orchestratormoderate
Authenticated Privilege Escalation in HPE EdgeConnect SD-WAN Orchestrator API
HPE Networking EdgeConnect SD-WAN Orchestrator contains privilege escalation flaws in its API that let a remote, low-privileged authenticated user escalate to administrative privileges. Exploitation is triggered by sending crafted requests to the orchestrator's API as any valid low-privilege account, with no user interaction required. A successful attacker gains full administrative control of the orchestrator, which HPE describes as leading to complete system compromise — and because the orchestrator centrally manages an organization's SD-WAN fabric, this also puts the wider network edge at risk. The issue affects customers running HPE Networking EdgeConnect SD-WAN Orchestrator (formerly Aruba EdgeConnect / Silver Peak Unity Orchestrator), in both on-premises and HPE-managed cloud deployments; specific affected versions were not stated in the advisory data. The flaw is rated critical (CVSS 9.9), but no public proof of concept exists, it is not in the CISA KEV catalog, and no in-the-wild exploitation is known.
· Hewlett Packard Enterprise (HPE) HPE Networking EdgeConnect SD-WAN Orchestratormoderate
Authenticated Privilege Escalation in HPE EdgeConnect SD-WAN Orchestrator API
CVE-2026-76669 is a critical (CVSS 3.1: 9.9) privilege escalation vulnerability in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. It is triggered remotely by a low-privileged authenticated user sending crafted requests to the affected API, exploiting flaws that let them elevate their rights to those of an administrative user. Successful exploitation grants full administrative control of the orchestrator, which HPE states leads to complete system compromise — and, given the orchestrator's role, potentially control over the SD-WAN fabric it manages. Any organization running an affected EdgeConnect SD-WAN Orchestrator deployment with multiple user accounts is exposed to risk, particularly where low-privileged or tenant-level API access exists. No public proof-of-concept is known and the flaw is not listed in CISA's KEV catalog, so exploitation status is currently none known.
· HPE (Hewlett Packard Enterprise) HPE Networking EdgeConnect SD-WAN Orchestratormoderate
Unauthenticated Buffer Overflow RCE in HPE EdgeConnect SD-WAN Gateways
CVE-2026-76674 is a critical (CVSS 9.8) buffer overflow vulnerability in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways (EdgeConnect OS/ECOS appliances). It is triggered remotely over the network with no authentication, no privileges, and no user interaction required, and successful exploitation allows an attacker to execute arbitrary commands on the gateway's OS, leading to complete system compromise of the appliance. Affected parties are enterprises and service providers operating HPE EdgeConnect SD-WAN branch or data-center gateways, especially any with management or data-plane services reachable from untrusted networks. Because gateways sit at the network edge, compromise can enable traffic interception or pivoting into internal corporate networks. No public proof of concept is known and the flaw is not in CISA's KEV catalog, so no active exploitation has been reported to date.
· Hewlett Packard Enterprise (HPE) HPE Networking EdgeConnect SD-WAN Gateway (EdgeConnect OS / ECOS)moderate
Unauthenticated Auth Bypass in HPE Aruba EdgeConnect SD-WAN Orchestrator API
CVE-2026-76673 is an authentication-bypass flaw in the API of HPE Aruba Networking's EdgeConnect SD-WAN Orchestrator that lets an unauthenticated remote attacker circumvent existing authentication controls over the network, with no privileges or user interaction required (CVSS 3.1: 9.8). Successful exploitation grants the attacker administrative privileges on the Orchestrator, which amounts to complete compromise of the Orchestrator host and, by extension, potential control over the managed SD-WAN fabric. Any organization operating an EdgeConnect SD-WAN Orchestrator (on-premises or provider/cloud-hosted) is affected, particularly instances whose API interface is reachable from untrusted networks. No public proof-of-concept is known, the flaw is not on CISA's KEV list, and there are no reports of in-the-wild exploitation as of this analysis. The high severity and network-exploitable nature still make patching urgent for exposed deployments.
· Hewlett Packard Enterprise (HPE Aruba Networking) EdgeConnect SD-WAN Orchestratormoderate