CVE-2025-37184: Arubanetworks Edgeconnect SD-WAN Orchestrator
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
A vulnerability exists in an Orchestrator service that could allow an unauthenticated remote attacker to bypass multi-factor authentication requirements. Successful exploitation could allow an attacker to create an admin user account without the necessary multi-factor authentication, thereby compromising the integrity of secured access to the system.
Affected products
- Arubanetworks Edgeconnect SD-WAN Orchestrator: from 9.2.0, up to and including 9.2.10; from 9.3.0, before 9.3.6 (fixed in 9.3.6); from 9.4.0, before 9.4.3 (fixed in 9.4.3); from 9.5.0, before 9.5.6 (fixed in 9.5.6); version 9.6.0 only
Published 2026-01-14. Last modified 2026-06-17.