logo

Critical HPE Vulnerabilities Allow Remote Attackers to Achieve Complete System Compromise

ID: 4efc7366-1620-5835-846b-5f552edb5d0a

STIX ID: report--4efc7366-1620-5835-846b-5f552edb5d0a

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-09-16

Date Updated: 2026-09-16

Author: Abinaya

...
...

Hewlett Packard Enterprise released a security bulletin (HPESBNW05135) disclosing multiple critical vulnerabilities in HPE EdgeConnect SD-WAN Orchestrator and Gateways (notably CVE-2026-76669, CVE-2026-76670, CVE-2026-76672–76674) that include API authorization/authentication bypasses, authenticated information disclosure, and unauthenticated buffer-overflow RCEs (CVSS up to 9.9). Affected ECOS and Orchestrator versions are listed with fixed releases available (ECOS 9.7.1.0+/Orchestrator 9.7.1+), and HPE recommends patching immediately and applying network isolation and firewall mitigations; no public exploit code or confirmed active exploitation was reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.