Vulnerabilities
HPE Aruba SD‑WAN Products Hit by Multiple Remote Code Execution and Privilege‑Escalation Flaws
HPE Aruba Networking has disclosed a set of critical flaws in its EdgeConnect SD‑WAN Gateways and Orchestrator that can be exploited for remote code execution, privilege escalation, and denial‑of‑service. Affected releases include Gateway 9.4.x‑9.7.x (pre‑9.4.9.0, 9.5.9.0, 9.6.4.0, 9.7.1.0) and Orchestrator 9.4.x‑9.7.x (pre‑9.4.11, 9.5.9, 9.6.4, 9.7.1.0). The CVE list ranges from CVE‑2024‑32664 to CVE‑2026‑76696. Patch the firmware immediately and follow HPE’s advisory for configuration hardening.
Overview
HPE Aruba Networking has identified a cluster of vulnerabilities that can be leveraged by an attacker to execute arbitrary code remotely, elevate privileges, and crash the system. The flaws also enable Server‑Side Request Forgery (SSRF) attacks, allowing malicious actors to probe internal networks.
Affected Products
- EdgeConnect SD‑WAN Gateways – versions 9.4.x.x (prior to 9.4.9.0), 9.5.x.x (prior to 9.5.9.0), 9.6.x.x (prior to 9.6.4.0), 9.7.x.x (prior to 9.7.1.0)
- EdgeConnect SD‑WAN Orchestrator – versions 9.4.x (prior to 9.4.11), 9.5.x (prior to 9.5.9), 9.6.x (prior to 9.6.4), 9.7.x (prior to 9.7.1.0)
Impact
- Remote code execution (RCE) – full control over the device
- Privilege escalation – gain root/administrator access
- Denial of service (DoS) – disrupt SD‑WAN connectivity
- SSRF – internal network reconnaissance and potential lateral movement
Mitigation
- Apply the latest firmware or security patches released in HPE Aruba Security Bulletin HPESBNW05135 (15 September 2026).
- Validate all external input and disable unused services on the gateway and orchestrator.
- Configure strict access controls and network segmentation to limit exposure.
- Monitor logs for anomalous API calls or unexpected traffic patterns.
Key CVE Identifiers
- CVE‑2024‑32664
- CVE‑2026‑76669 through CVE‑2026‑76696 (inclusive)
Immediate patching is essential. Contact your HPE Aruba support representative if you are unsure whether your devices are affected or if you need assistance applying the updates.