Critical HPE Vulnerabilities Allow Remote Attackers to Achieve Complete System Compromise

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Hewlett Packard Enterprise has released security updates for HPE Networking EdgeConnect SD-WAN Gateways and SD-WAN Orchestrator after identifying dozens of vulnerabilities, including critical flaws that could let remote attackers take full control of affected systems.

HPE tracks the issues in Security Bulletin HPESBNW05135, published on September 15, 2026. The most severe vulnerabilities affect the management interfaces and application programming interfaces used by EdgeConnect SD-WAN deployments.

HPE said customers should install the available updates as soon as possible because successful exploitation could expose credentials, allow arbitrary command execution, disrupt network operations, or fully compromise an Orchestrator host or gateway appliance.

Critical HPE Vulnerabilities

The critical vulnerabilities include CVE-2026-76669 and CVE-2026-76670, which are authorization bypass issues in the EdgeConnect SD-WAN Orchestrator API.

A remote attacker with low-privilege authenticated access could exploit the flaws to elevate privileges to administrator level. Both vulnerabilities received a CVSS score of 9.9.

Another critical issue, CVE-2026-76672, can expose sensitive configuration information from the Orchestrator. A read-only authenticated user could send a specially crafted request to a cache synchronization endpoint and obtain third-party API tokens and credentials.

HPE warned that stolen credentials could enable lateral movement into connected external security platforms. The flaw also carries a CVSS score of 9.9.

HPE disclosed CVE-2026-76673, a critical Orchestrator API authentication bypass flaw (CVSS 9.8) that could let unauthenticated remote attackers gain administrative privileges and fully compromise the host without a valid account.

A second CVSS 9.8 vulnerability, CVE-2026-76674, affects EdgeConnect SD-WAN Gateways. The issue involves buffer overflows in the underlying operating system.

Critical Vulnerabilities:

CVE Affected Product Vulnerability Type CVSS v3.1
CVE-2026-76669 HPE EdgeConnect SD-WAN Orchestrator API Authorization Bypass / Privilege Escalation 9.9
CVE-2026-76670 HPE EdgeConnect SD-WAN Orchestrator API Authorization Bypass / Privilege Escalation 9.9
CVE-2026-76672 HPE EdgeConnect SD-WAN Orchestrator Authenticated Information Disclosure 9.9
CVE-2026-76673 HPE EdgeConnect SD-WAN Orchestrator API Authentication Bypass 9.8
CVE-2026-76674 HPE EdgeConnect SD-WAN Gateways Unauthenticated Buffer Overflow / RCE 9.8

An unauthenticated remote attacker could exploit the vulnerability to run arbitrary code and commands on the affected device, potentially gaining full control of the gateway.

The advisory also covers high-severity command injection, buffer overflow, server-side request forgery, information disclosure, privilege escalation, and denial-of-service vulnerabilities.

Several flaws can allow authenticated low-privilege users to execute commands with root privileges, while others may let unauthenticated attackers crash services or access sensitive system information.

Affected Gateway releases include ECOS 9.7.0.0 and earlier, 9.6.3.1 and earlier, 9.5.8.1 and earlier, and 9.4.8.2 and earlier. Impacted Orchestrator releases include version 9.7.0 and earlier, 9.6.3 and earlier, 9.5.8 and earlier, and 9.4.10 and earlier.

HPE has fixed the vulnerabilities in ECOS 9.7.1.0, 9.6.4.0, 9.5.9.0, and 9.4.9.0 or later. For Orchestrator, organizations should upgrade to versions 9.7.1, 9.6.4, 9.5.9, or 9.4.11 or later. HPE noted that the Orchestrator version must be equal to or newer than the ECOS release running on managed gateways.

As a temporary defensive measure, HPE recommends isolating command-line and web management interfaces on a dedicated Layer 2 segment or VLAN, enforcing Layer 3 firewall policies, and logging administrative activity. HPE said it was not aware of public exploit code or active exploitation when it released the bulletin.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Critical HPE Vulnerabilities Allow Remote Attackers to Achieve Complete System Compromise appeared first on Cyber Security News.