HPE EdgeConnect SD-WAN vulnerabilities disclosed in September 2026 affect supported EdgeConnect SD-WAN Gateway and Orchestrator branches, but the flaws do not all have the same attack prerequisites. HPE has published fixed releases, so the practical task for administrators is to identify the exact product and software branch they run, then compare it with the relevant fixed-version threshold.
Which HPE EdgeConnect versions are fixed?
The remediation path differs between ECOS Gateway and Orchestrator. Based on the reviewed HPE advisory and corroborating government CERT material, the fixed release thresholds are:
| Product branch | Fixed release |
|---|---|
| ECOS 9.4.x | 9.4.9.0 or later |
| ECOS 9.5.x | 9.5.9.0 or later |
| ECOS 9.6.x | 9.6.4.0 or later |
| ECOS 9.7.x | 9.7.1.0 or later |
| Orchestrator 9.4.x | 9.4.11 or later |
| Orchestrator 9.5.x | 9.5.9 or later |
| Orchestrator 9.6.x | 9.6.4 or later |
| Orchestrator 9.7.x | 9.7.1 or later |
Why the individual CVEs must be separated
The vulnerability set includes several high-severity conditions with different exposure requirements. CVE-2026-76673 is an unauthenticated Orchestrator authentication-bypass issue, while CVE-2026-76674 is an unauthenticated Gateway remote-code-execution issue. Other flaws require an authenticated user or higher privileges. That means it would be inaccurate to describe the entire advisory as one unauthenticated RCE condition.
Confirm whether the system is an EdgeConnect SD-WAN Gateway running ECOS or an EdgeConnect Orchestrator.
Check the installed software branch and compare it with the appropriate fixed threshold rather than using a generic 9.x assumption.
Move to the applicable HPE-fixed release according to the current vendor advisory and your supported upgrade path.
Review management-plane exposure and watch for later HPE revisions, exploitation evidence or CISA escalation.
Is active exploitation confirmed?
TPS did not find verified evidence during the completed review that this HPE EdgeConnect vulnerability set is currently being exploited in the wild. That should not be interpreted as proof that exploitation is impossible. Administrators should treat the vendor fixes as actionable remediation and continue monitoring HPE, CISA and relevant CERT advisories for any change in exploitation status.
What administrators should do now
Inventory the exact EdgeConnect product and version, match it to the fixed-version table, and validate the supported upgrade path against the current HPE security bulletin before changing production infrastructure. Where practical, restrict access to management interfaces while remediation is pending. The most important distinction is that Gateway and Orchestrator versions, impacts and authentication requirements are not interchangeable.