# CVE-2026-76689

## Summary

- **CVE ID:** CVE-2026-76689
- **Severity:** HIGH
- **CVSS Score:** 7.2 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Sep 15, 2026
- **Last Modified:** Sep 15, 2026

## Description

A vulnerability exists in the configuration processing logic of the affected component where malformed input is improperly processed. An authenticated remote attacker with administrative privileges could exploit this vulnerability by providing specially crafted configuration data. Successful exploitation could result in a stack-based buffer overflow, potentially leading to remote code execution with root privileges or a denial of service due to a system crash.

## Affected Products

- Hewlett Packard Enterprise (HPE) — EdgeConnect SD-WAN Gateways (9.7.0.0)
- Hewlett Packard Enterprise (HPE) — EdgeConnect SD-WAN Gateways (9.6.0.0)
- Hewlett Packard Enterprise (HPE) — EdgeConnect SD-WAN Gateways (9.5.0.0)
- Hewlett Packard Enterprise (HPE) — EdgeConnect SD-WAN Gateways (9.4.0.0)

## References

- [CNA](https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.85%
- **EPSS Percentile:** 56.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._