Vulnerabilities · 4 days ago

HPE EdgeConnect Fixes Reach Into the Control Plane

HPE disclosed 39 vulnerabilities in EdgeConnect SD-WAN, including six critical issues that affect both Networking EdgeConnect SD-WAN Gateways and the Orchestrator across the 9.4.x to 9.7.x branches. INCIBE-CERT says the risky builds include older ECOS gateway releases and matching Orchestrator versions in the same trains.

Some of the flaws let a low-privileged or unauthenticated requester send a crafted API call that the product mishandles, turning it into admin access, privilege escalation, or code execution. In one case, an authenticated read-only user could pull sensitive configuration data, including API tokens and third-party credentials, from the Orchestrator cache-sync endpoint.

That puts the management plane and the edge boxes in the same exposure chain: if the Orchestrator is compromised, the attacker can reach fleet-wide configuration and credentials, while Gateway flaws can land code execution at the edge. HPE also says the Orchestrator version must be at least as new as the ECOS version on any managed gateway, so mixed estates inherit a patch-coordination problem, not just a software-update problem.

CVEs in this update

6 CVEs

Across EdgeConnect, EdgeConnect SD-WAN Gateways.

6 critical · 0 high · 0 medium · 0 low

0 in CISA KEV · 2 with EPSS above 1%

Highest severity: CVE-2026-76669 · 9.9 CRITICAL

Highest EPSS: CVE-2026-76675 · 1.3%

Timeline

Sources

2 sources covering this story

Entities

Part of the PlainSec briefing for 2026-09-18

Editions

Related stories