Junglewise Threat Intelligence

CVE-2026-76683: HPE EdgeConnect SD-WAN Gateway buffer overflow in API endpoint

CVE-2026-76683 · Severity: high · CVSS 8.1 · Published 2026-09-15

Executive brief

HPE Networking EdgeConnect SD-WAN Gateways are network appliances used to manage and optimize branch office connectivity. A buffer overflow vulnerability in the API endpoint could allow unauthenticated attackers to execute arbitrary commands on the underlying system, potentially leading to complete compromise of the gateway and disruption of branch network operations.

Technical details

A buffer overflow vulnerability exists in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways that can be triggered by an unauthenticated remote attacker. The vulnerability allows execution of arbitrary commands on the underlying operating system, though successful exploitation requires certain preconditions outside of the attacker's direct control. The flaw is in the API request handling component and could lead to complete system compromise if exploited.

Affected products

  • HPE EdgeConnect SD-WAN Gateway

Timeline

  • 2026-09-15: disclosed

References

Related threats