Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
6354 articles · 219798 vulns · 36/41 feeds (7d)
← Back to list
8.5
CVE-2026-76680
hewlett packard enterprise (hpe) · edgeconnect sd-wan gateways

Authenticated Server-Side Request Forgery Vulnerabilities Leading to Information Disclosure in EdgeConnect SD-WAN Orchestrator

Description

Vulnerabilities in the API of EdgeConnect SD-WAN Orchestrator could allow a remote attacker authenticated with low privileges to conduct server-side request forgery (SSRF) attacks. A successful exploit allows an attacker to enumerate information about the internal structure of the EdgeConnect SD-WAN Orchestrator host leading to potential disclosure of sensitive information beyond what is authorized by the user's existing privilege level.

Affected Products

VendorProductVersions
hewlett packard enterprise (hpe)edgeconnect sd-wan gateways9.7.0, 9.6.0, 9.5.0, 9.4.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
arubaedgeconnectcert_advisory90%

References

  • https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US

Related News (3 articles)

Tier B
BSI Advisories4d ago
[NEU] [hoch] Aruba EdgeConnect: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR4d ago
Multiples vulnérabilités dans les produits HPE Aruba Networking (16 septembre 2026)
→ No new info (linked only)
Tier C
VulDB4d ago
CVE-2026-76680 | HPE EdgeConnect SD-WAN Gateways up to 9.4.10/9.5.8/9.6.3/9.7.0 API server-side request forgery
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.18.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
CISA KEV❌ No
Actively exploited❌ No
PublishedSep 15, 2026
Trending Score26
Source articles3
Independent3
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-76672
Authenticated Sensitive Information Disclosure in HPE Networking EdgeConnect SD-WAN Orchestrator
Trending: 28
MEDIUMCVE-2026-76706
Unauthenticated Information Disclosure in EdgeConnect SD-WAN Orchestrator API allows exposure of sensitive data
Trending: 27
MEDIUMCVE-2026-76695
Unauthenticated Buffer Overflow Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways
Trending: 27
HIGHCVE-2026-76688
Authentication Bypass Vulnerabilities in the Web-Based Management Interface of EdgeConnect SD-WAN Orchestrator
Trending: 26
HIGHCVE-2026-76681
Authenticated Information Disclosure Vulnerability in HPE Networking EdgeConnect SD-WAN Orchestrator API
Trending: 26

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 15, 2026
Discovered by ZDM
Sep 15, 2026