Junglewise Threat Intelligence

CVE-2026-76692: HPE EdgeConnect SD-WAN Gateway information disclosure and denial of service

CVE-2026-76692 · Severity: high · CVSS 7.1 · Published 2026-09-15

Executive brief

HPE EdgeConnect is a SD-WAN gateway used to optimize and secure branch network traffic. An unauthenticated attacker on an adjacent network can trigger a crash or leak uninitialized memory from the device, disrupting network operations and potentially exposing sensitive data.

Technical details

This vulnerability allows an unauthenticated, adjacent network attacker to obtain limited information from memory and cause denial of service in HPE EdgeConnect SD-WAN Gateways. The attack exploits an uninitialized memory disclosure or memory handling issue accessible without authentication, requiring only network adjacency. Successful exploitation results in either a system crash (DoS) or disclosure of uninitialized stack memory containing sensitive information. No patch information is currently known to be available.

Affected products

  • HPE EdgeConnect SD-WAN Gateway <UNKNOWN>

Timeline

  • 2026-09-15: disclosed

References

Related threats