Hewlett Packard Enterprise has released security updates for its EdgeConnect SD-WAN Gateways and SD-WAN Orchestrator following the identification of 40 vulnerabilities, including multiple critical flaws that could allow attackers to gain administrative control or execute arbitrary code.

CVE Affected product Vulnerability / impact CVE-2026-76669 Orchestrator API authorization bypass; low-privilege user can escalate to admin CVE-2026-76670 Orchestrator API authorization bypass; low-privilege user can escalate to admin CVE-2026-76672 Orchestrator Authenticated disclosure of tokens and credentials CVE-2026-76673 Orchestrator Unauthenticated API authentication bypass; admin takeover CVE-2026-76674 Gateway Unauthenticated OS buffer overflow; remote code execution CVE-2026-76675 Gateway Authenticated CLI command injection; privileged command execution CVE-2026-76676 Gateway Adjacent unauthenticated buffer overflow; code execution CVE-2026-76677 Gateway API authorization bypass; elevation to web-management admin CVE-2026-76678 Gateway Authenticated API command injection; root command execution CVE-2026-76679 Gateway Unauthenticated denial of service; appliance crash CVE-2026-76680 Orchestrator Authenticated SSRF and internal-information disclosure CVE-2026-76681 Orchestrator Authenticated API information disclosure CVE-2026-76682 Gateway Unauthenticated buffer overflow; DoS or potential code execution CVE-2026-76683 Gateway Unauthenticated API buffer overflow; remote command execution CVE-2026-76684 Orchestrator Unauthenticated API authentication bypass; admin takeover CVE-2026-76685 Gateway Proxy-processing integer/buffer overflow; RCE or DoS CVE-2026-76686 Gateway Unauthenticated remote denial of service CVE-2026-76687 Orchestrator Authenticated arbitrary file write; root command execution CVE-2026-76688 Orchestrator Web-management authentication bypass CVE-2026-76689 Gateway Authenticated configuration buffer overflow; root RCE or DoS CVE-2026-76690 Gateway Authenticated remote code execution as root CVE-2026-76691 Gateway Authenticated API buffer overflow; privileged command execution CVE-2026-76692 Gateway Adjacent memory disclosure and denial of service CVE-2026-76693 Gateway Unauthenticated remote denial of service CVE-2026-76694 Gateway Authenticated CLI privilege escalation CVE-2026-76695 Gateway Unauthenticated buffer overflow affecting integrity and availability CVE-2026-76696 Gateway Adjacent unauthenticated denial of service CVE-2026-76697 Gateway Authenticated web-management information disclosure CVE-2026-76698 Gateway Authenticated command injection; DoS or elevated command execution CVE-2026-76699 Gateway Adjacent buffer overflow; denial of service CVE-2026-76700 Gateway Unauthenticated denial of service CVE-2026-76701 Gateway Unauthenticated API sensitive-information disclosure CVE-2026-76702 Gateway Authenticated local denial of service CVE-2026-76703 Gateway Authenticated web-interface buffer overflow; denial of service CVE-2026-76704...