Critical HPE RMC, OneView, and iLO 5 Flaws Let Attackers Remotely Execute Code
Key Takeaways HPE has released urgent security updates addressing numerous vulnerabilities, including five critical flaws, in its EdgeConnect SD-WAN Gateways and Orchestrator products. These critical...
Key Takeaways
- HPE has released urgent security updates addressing numerous vulnerabilities, including five critical flaws, in its EdgeConnect SD-WAN Gateways and Orchestrator products.
- These critical vulnerabilities could enable remote attackers to achieve full system compromise, execute arbitrary code, or gain administrative privileges.
- Impacted versions include ECOS 9.7.0.0 and earlier, and Orchestrator 9.7.0 and earlier, across multiple release branches.
- Customers are strongly advised to apply the available patches immediately to mitigate severe risks, including credential exposure and network disruption.
Hewlett Packard Enterprise (HPE) has issued a critical security bulletin detailing dozens of vulnerabilities across its Networking EdgeConnect SD-WAN Gateways and SD-WAN Orchestrator. Among these are several critical flaws that could allow remote attackers to seize complete control of affected systems.
Table Of Content
The issues, documented in HPE Security Bulletin HPESBNW05135, were published on September 15, 2026. The most severe vulnerabilities specifically target the management interfaces and application programming interfaces (APIs) inherent to EdgeConnect SD-WAN deployments.
HPE has urged its customers to promptly install the available updates. The company highlighted that successful exploitation of these vulnerabilities could lead to the exposure of sensitive credentials, arbitrary command execution, disruption of network operations, or even the full compromise of an Orchestrator host or gateway appliance.
Critical HPE Vulnerabilities Uncovered
The most severe vulnerabilities identified include CVE-2026-76669 and CVE-2026-76670. Both are authorization bypass flaws found within the EdgeConnect SD-WAN Orchestrator API.
These particular vulnerabilities could be exploited by a remote attacker with existing low-privilege authenticated access to escalate their privileges to an administrator level. Both CVEs have been assigned a CVSS score of 9.9, indicating their critical severity.
Another critical issue, CVE-2026-76672, poses a risk of exposing sensitive configuration information from the Orchestrator. An authenticated user with read-only permissions could craft a specific request to a cache synchronization endpoint, potentially obtaining third-party API tokens and credentials. HPE warned that compromised credentials from this vulnerability could facilitate lateral movement into connected external security platforms. This flaw also carries a CVSS score of 9.9.
HPE also disclosed CVE-2026-76673, a critical Orchestrator API authentication bypass vulnerability with a CVSS score of 9.8. This flaw could enable unauthenticated remote attackers to gain administrative privileges and fully compromise the host without requiring a valid user account.
A second vulnerability rated CVSS 9.8, CVE-2026-76674, impacts EdgeConnect SD-WAN Gateways. This issue stems from buffer overflows within the underlying operating system. An unauthenticated remote attacker could leverage this vulnerability to execute arbitrary code and commands on the affected device, potentially achieving complete control over the gateway.
Summary of Critical Vulnerabilities
| CVE | Affected Product | Vulnerability Type | CVSS v3.1 |
|---|---|---|---|
| CVE-2026-76669 | HPE EdgeConnect SD-WAN Orchestrator | API Authorization Bypass / Privilege Escalation | 9.9 |
| CVE-2026-76670 | HPE EdgeConnect SD-WAN Orchestrator | API Authorization Bypass / Privilege Escalation | 9.9 |
| CVE-2026-76672 | HPE EdgeConnect SD-WAN Orchestrator | Authenticated Information Disclosure | 9.9 |
| CVE-2026-76673 | HPE EdgeConnect SD-WAN Orchestrator | API Authentication Bypass | 9.8 |
| CVE-2026-76674 | HPE EdgeConnect SD-WAN Gateways | Unauthenticated Buffer Overflow / RCE | 9.8 |
Beyond these critical findings, the advisory also details numerous high-severity vulnerabilities, encompassing command injection, additional buffer overflows, server-side request forgery, information disclosure, privilege escalation, and denial-of-service flaws. Several of these issues could allow authenticated low-privilege users to execute commands with root privileges, while others might enable unauthenticated attackers to crash services or access sensitive system information.
Affected Gateway releases include ECOS 9.7.0.0 and earlier, 9.6.3.1 and earlier, 9.5.8.1 and earlier, and 9.4.8.2 and earlier. For the Orchestrator, impacted versions include 9.7.0 and earlier, 9.6.3 and earlier, 9.5.8 and earlier, and 9.4.10 and earlier.
HPE has fixed the vulnerabilities in ECOS versions 9.7.1.0, 9.6.4.0, 9.5.9.0, and 9.4.9.0 or later. For the Orchestrator, organizations should upgrade to versions 9.7.1, 9.6.4, 9.5.9, or 9.4.11 or later. HPE emphasized that the Orchestrator version must be equal to or newer than the ECOS release running on managed gateways.
As a temporary defensive measure, HPE advises isolating command-line and web management interfaces on a dedicated Layer 2 segment or VLAN, enforcing robust Layer 3 firewall policies, and diligently logging all administrative activity. At the time of the bulletin’s release, HPE stated it was not aware of any public exploit code or active exploitation in the wild.
What You Should Do
- Immediately Apply Patches: Upgrade HPE EdgeConnect SD-WAN Gateways to ECOS versions 9.7.1.0, 9.6.4.0, 9.5.9.0, 9.4.9.0, or later. Update HPE EdgeConnect SD-WAN Orchestrator to versions 9.7.1, 9.6.4, 9.5.9, 9.4.11, or later. Ensure your Orchestrator version is equal to or newer than the ECOS release on managed gateways.
- Isolate Management Interfaces: Place command-line and web management interfaces on a dedicated Layer 2 segment or VLAN, separate from the operational network.
- Enforce Firewall Policies: Implement strict Layer 3 firewall policies to restrict access to management interfaces to only necessary administrative sources.
- Monitor and Log: Continuously log and monitor all administrative activity for suspicious behavior.
- Review Access Controls: Regularly audit and minimize user privileges, especially for API access, following the principle of least privilege.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.