---
id: CVE-2026-76674
title: >-
  Buffer overflow vulnerabilities exist in the underlying operating system of
  HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated
  remote attacker to execute arbitrary code
summary: >-
  Buffer overflow vulnerabilities exist in the underlying operating system of
  HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated
  remote attacker to execute arbitrary code. Successful exploitation could allow
  an …
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-120
vendor: Hewlett Packard Enterprise (HPE)
product: EdgeConnect SD-WAN Gateways
affected:
  - edgeconnect_sd-wan_gateways >= 9.7.0.0 <= 9.7.0.0
  - edgeconnect_sd-wan_gateways >= 9.6.0.0 <= 9.6.3.1
  - edgeconnect_sd-wan_gateways >= 9.5.0.0 <= 9.5.8.1
  - edgeconnect_sd-wan_gateways >= 9.4.0.0 <= 9.4.8.2
published: '2026-09-15'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T20:17:29.583'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76674'
references:
  - url: >-
      https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US
    label: security-alert@hpe.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-21T19:59:21.174909Z'
epss: 0.01014
epssPercentile: 0.61724
ingestedAt: '2026-09-15T19:42:58.831Z'
---

## Overview

Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to execute arbitrary code. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
