Hewlett Packard Enterprise released bulletin HPESBNW05135 rev.1 to remediate dozens of vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways and EdgeConnect SD-WAN Orchestrator. Five critical issues, CVE-2026-76669 through CVE-2026-76674, carry CVSS scores of 9.8–9.9 and include authentication and authorization bypasses, information disclosure, and an unauthenticated buffer-overflow remote-code-execution flaw. An attacker could gain administrator or root-level access, steal third-party API credentials, execute arbitrary commands, disrupt services, and fully compromise gateway appliances or Orchestrator hosts.
HPE has issued fixed ECOS and Orchestrator releases and urged customers to upgrade promptly. Organizations should isolate management interfaces, restrict access with Layer 3 firewall rules, and monitor administrative activity while updates are deployed. HPE reported no known public exploit code or active exploitation when the bulletin was published; the Canadian Centre for Cyber Security and Guyana National CIRT also advised affected administrators to review HPE’s guidance and apply the required updates.

Map this exposure pattern across your cloud, code, and identities.
2 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security issued advisory AV26-928 referencing HPE bulletin HPESBNW05135 and advised users and administrators to review HPE's guidance and apply necessary updates.
HPE published security bulletin HPESBNW05135 revision 1 addressing dozens of vulnerabilities in EdgeConnect SD-WAN Gateways and Orchestrator, including CVE-2026-76669 through CVE-2026-76674. The bulletin provided fixed ECOS and Orchestrator releases; the most severe flaws could enable privilege escalation, credential disclosure, authentication bypass, or remote code execution, and HPE reported no known public exploit code or active exploitation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
4 references tracked. Mallory keeps watching after this page renders.
cirt.gy
Open sourcecyber.gc.ca
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.