Junglewise Threat Intelligence

CVE-2026-76707: HPE EdgeConnect SD-WAN Gateway information disclosure via memory access

CVE-2026-76707 · Severity: medium · CVSS 4.3 · Published 2026-09-15

Executive brief

HPE EdgeConnect SD-WAN Gateways are network appliances used to optimize and secure wide-area network traffic. An unauthenticated attacker on the same network segment can read portions of system memory, potentially exposing internal service details and configuration data that could be chained with other attacks to gain unauthorized access or elevated privileges.

Technical details

This is an information disclosure vulnerability in HPE EdgeConnect SD-WAN Gateways that allows an unauthenticated adjacent attacker to read arbitrary system memory contents. The vulnerability requires network adjacency (same local network segment) but no authentication. Successful exploitation leaks sensitive data about internal services and workflows, which can be leveraged in multi-stage attacks to escalate privileges or gain unauthorized access. The attack combines memory disclosure with other vulnerabilities to achieve meaningful impact. A patch is available from HPE.

Affected products

  • HPE EdgeConnect SD-WAN Gateway

Timeline

  • 2026-09-15: disclosed

References

Related threats