CVE-2026-76675: Arubanetworks Edgeconnect SD-WAN Orchestrator

Critical severity, CVSS 9.1. EPSS: 1.5% chance of exploitation in the next 30 days.

A command injection vulnerability exists in the command line interface of EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with high privileges to execute arbitrary commands on the underlying operating system leading to complete system compromise.

Affected products

  • Arubanetworks Edgeconnect SD-WAN Orchestrator: from 9.4.0, before 9.4.11 (fixed in 9.4.11); from 9.5.0, before 9.5.9 (fixed in 9.5.9); from 9.6.0, before 9.6.4 (fixed in 9.6.4); version 9.7.0 only
  • HPE Edgeconnect Operating System: from 9.4.0.0, before 9.4.9.0 (fixed in 9.4.9.0); from 9.5.0.0, before 9.5.9.0 (fixed in 9.5.9.0); from 9.6.0.0, before 9.6.4.0 (fixed in 9.6.4.0); version 9.7.0.0 only

Published 2026-09-15. Last modified 2026-09-28.