Hewlett Packard Enterprise disclosed multiple high-severity vulnerabilities in HPE EdgeConnect SD-WAN Orchestrator that can let an unauthenticated remote attacker bypass web authentication by spoofing HTTP headers in the product's REST API. The issues, tracked as CVE-2026-63455 and CVE-2026-63456, could expose system functions and allow viewing or modification of sensitive information, with potential impact to confidentiality, integrity, and availability. Both CVEs carry a CVSS v3.1 rating of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
Affected releases include 9.6.2.00000 through 9.6.2.40208 and 9.6.3.00000 through 9.6.3.40137, which Canadian Centre for Cyber Security guidance summarized as 9.6.2.40208 and earlier and 9.6.3.40137 and earlier. HPE's bulletin HPESBNW05100 rev.1 and related government advisories urge administrators to review the vendor guidance and apply updates as they become available to reduce exposure in internet-reachable orchestration environments.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
On August 5, 2026, the Canadian Centre for Cyber Security published advisory AV26-778 warning that HPE EdgeConnect SD-WAN Orchestrator 9.6.2.40208 and earlier and 9.6.3.40137 and earlier are affected by multiple vulnerabilities. The notice referenced HPE bulletin HPESBNW05100 rev.1 and advised users to review guidance and apply updates when available.
The CVE record states that CVE-2026-63456 was received by security-alert@hpe.com on August 4, 2026. It describes multiple REST API vulnerabilities in HPE EdgeConnect SD-WAN Orchestrator that could allow unauthenticated authentication bypass and access to system functions.
The CVE record states that CVE-2026-63455 was received by security-alert@hpe.com on August 4, 2026. It describes multiple REST API vulnerabilities in HPE EdgeConnect SD-WAN Orchestrator that could allow unauthenticated authentication bypass and access to system functions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.