Junglewise Threat Intelligence

CVE-2026-76679: HPE EdgeConnect SD-WAN denial of service

CVE-2026-76679 · Severity: high · CVSS 8.6 · Published 2026-09-15

Executive brief

HPE EdgeConnect SD-WAN Gateways are network devices that manage branch office connectivity and optimize WAN traffic. An unauthenticated attacker on the same network segment can crash these gateways, causing them to stop operating and preventing automatic recovery, which disrupts branch office network operations and may require manual intervention to restore service.

Technical details

This vulnerability allows an unauthenticated, adjacent-network attacker to conduct a denial-of-service attack against HPE EdgeConnect SD-WAN Gateways, resulting in a system crash. The attacker does not require authentication or remote network access—only layer 2 adjacency—making it exploitable from a connected switch or wireless network segment. Successful exploitation causes the gateway to crash in a state from which it cannot automatically reboot, requiring manual intervention to restore operation. The root cause and vulnerable component are not specified in the provided advisory content, but the impact is total service unavailability for the affected gateway.

Affected products

  • HPE EdgeConnect SD-WAN <UNKNOWN>

Timeline

  • 2026-09-15: disclosed

References