Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
6354 articles · 219798 vulns · 36/41 feeds (7d)
← Back to list
7.5
CVE-2026-76688
Hewlett Packard Enterprise (HPE) · EdgeConnect SD-WAN Gateways

Authentication Bypass Vulnerabilities in the Web-Based Management Interface of EdgeConnect SD-WAN Orchestrator

Description

Vulnerabilities have been identified in the web-based management interface of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the EdgeConnect SD-WAN Orchestrator host.

Affected Products

VendorProductVersions
Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateways9.7.0, 9.6.0, 9.5.0, 9.4.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
arubaedgeconnectcert_advisory90%

References

  • https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US

Related News (3 articles)

Tier B
BSI Advisories4d ago
[NEU] [hoch] Aruba EdgeConnect: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR4d ago
Multiples vulnérabilités dans les produits HPE Aruba Networking (16 septembre 2026)
→ No new info (linked only)
Tier C
VulDB4d ago
CVE-2026-76688 | HPE EdgeConnect SD-WAN Gateways up to 9.4.10/9.5.8/9.6.3/9.7.0 Web-based Management Interface improper authentication
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
PublishedSep 15, 2026
Last enriched4d ago
Trending Score26
Source articles3
Independent3
Info Completeness7/14
Missing: epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-76672
Authenticated Sensitive Information Disclosure in HPE Networking EdgeConnect SD-WAN Orchestrator
Trending: 28
MEDIUMCVE-2026-76706
Unauthenticated Information Disclosure in EdgeConnect SD-WAN Orchestrator API allows exposure of sensitive data
Trending: 27
MEDIUMCVE-2026-76695
Unauthenticated Buffer Overflow Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways
Trending: 27
HIGHCVE-2026-76680
Authenticated Server-Side Request Forgery Vulnerabilities Leading to Information Disclosure in EdgeConnect SD-WAN Orchestrator
Trending: 26
HIGHCVE-2026-76681
Authenticated Information Disclosure Vulnerability in HPE Networking EdgeConnect SD-WAN Orchestrator API
Trending: 26

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 15, 2026
Discovered by ZDM
Sep 15, 2026