LATEST View all updates

HPE EdgeConnect SD-WAN Vulnerabilities: Affected Versions and Fixed Releases

HPE fixed multiple EdgeConnect SD-WAN flaws. Check affected Gateway and Orchestrator branches before upgrading.

Enterprise SD-WAN appliance and patching illustration for HPE EdgeConnect SD-WAN vulnerabilities

Signal Brief

  • HPE has released fixed versions for affected EdgeConnect SD-WAN Gateway and Orchestrator branches.
  • The vulnerability set includes both unauthenticated flaws and flaws that require existing privileges.
  • Administrators should verify the exact product and branch before choosing a fixed release.
  • TPS did not verify active exploitation of this vulnerability set during the completed review.

HPE EdgeConnect SD-WAN vulnerabilities disclosed in September 2026 affect supported EdgeConnect SD-WAN Gateway and Orchestrator branches, but the flaws do not all have the same attack prerequisites. HPE has published fixed releases, so the practical task for administrators is to identify the exact product and software branch they run, then compare it with the relevant fixed-version threshold.

Which HPE EdgeConnect versions are fixed?

The remediation path differs between ECOS Gateway and Orchestrator. Based on the reviewed HPE advisory and corroborating government CERT material, the fixed release thresholds are:

Product branch Fixed release
ECOS 9.4.x 9.4.9.0 or later
ECOS 9.5.x 9.5.9.0 or later
ECOS 9.6.x 9.6.4.0 or later
ECOS 9.7.x 9.7.1.0 or later
Orchestrator 9.4.x 9.4.11 or later
Orchestrator 9.5.x 9.5.9 or later
Orchestrator 9.6.x 9.6.4 or later
Orchestrator 9.7.x 9.7.1 or later

Why the individual CVEs must be separated

The vulnerability set includes several high-severity conditions with different exposure requirements. CVE-2026-76673 is an unauthenticated Orchestrator authentication-bypass issue, while CVE-2026-76674 is an unauthenticated Gateway remote-code-execution issue. Other flaws require an authenticated user or higher privileges. That means it would be inaccurate to describe the entire advisory as one unauthenticated RCE condition.

Identify the component

Confirm whether the system is an EdgeConnect SD-WAN Gateway running ECOS or an EdgeConnect Orchestrator.

Record the exact version

Check the installed software branch and compare it with the appropriate fixed threshold rather than using a generic 9.x assumption.

Apply the supported update

Move to the applicable HPE-fixed release according to the current vendor advisory and your supported upgrade path.

Recheck exposure

Review management-plane exposure and watch for later HPE revisions, exploitation evidence or CISA escalation.

Is active exploitation confirmed?

TPS did not find verified evidence during the completed review that this HPE EdgeConnect vulnerability set is currently being exploited in the wild. That should not be interpreted as proof that exploitation is impossible. Administrators should treat the vendor fixes as actionable remediation and continue monitoring HPE, CISA and relevant CERT advisories for any change in exploitation status.

What administrators should do now

Inventory the exact EdgeConnect product and version, match it to the fixed-version table, and validate the supported upgrade path against the current HPE security bulletin before changing production infrastructure. Where practical, restrict access to management interfaces while remediation is pending. The most important distinction is that Gateway and Orchestrator versions, impacts and authentication requirements are not interchangeable.

Public provenanceVerification & change history

This log separates publication, substantive reader-facing updates and source-verification checks. Older maintenance activity may predate detailed public logging.

  1. Verified

    TPS completed a source-verification pass.

  2. Published

    Article first published.

Trust boundary

Disclaimer

ThePulseSignal (TPS) provides this evidence-led cybersecurity article for informational and editorial guidance. HPE EdgeConnect exposure depends on the exact Gateway or Orchestrator version and the individual CVE; not every flaw has the same authentication requirement or impact. TPS did not verify active exploitation of this vulnerability set. Before changing production infrastructure, verify the current HPE security bulletin and your supported upgrade path.