---
id: CVE-2026-76683
title: >-
  Buffer overflow vulnerabilities exist in the API endpoint of HPE Networking
  EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote
  attacker to run arbitrary commands on the underlying host if certain
  preconditions outside…
summary: >-
  Buffer overflow vulnerabilities exist in the API endpoint of HPE Networking
  EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote
  attacker to run arbitrary commands on the underlying host if certain
  preconditions outside…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-120
vendor: Hewlett Packard Enterprise (HPE)
product: EdgeConnect SD-WAN Gateways
affected:
  - edgeconnect_sd-wan_gateways >= 9.7.0.0 <= 9.7.0.0
  - edgeconnect_sd-wan_gateways >= 9.6.0.0 <= 9.6.3.1
  - edgeconnect_sd-wan_gateways >= 9.5.0.0 <= 9.5.8.1
  - edgeconnect_sd-wan_gateways >= 9.4.0.0 <= 9.4.8.2
published: '2026-09-15'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T20:17:31.357'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76683'
references:
  - url: >-
      https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US
    label: security-alert@hpe.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-21T19:57:43.648549Z'
epss: 0.00589
epssPercentile: 0.46572
ingestedAt: '2026-09-15T19:42:58.827Z'
---

## Overview

Buffer overflow vulnerabilities exist in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
