VORANT. Threat Intelligence Sign in Get the full feed

Aruba EdgeConnect SD-WAN Orchestrator flaws patched

medium vulnerability telecommunicationsinfrastructure

HPE Aruba Networking patched two vulnerabilities in EdgeConnect SD-WAN Orchestrator that could allow data confidentiality/integrity breaches and security policy bypass.

CERT-FR issued an advisory covering multiple vulnerabilities in HPE Aruba Networking's EdgeConnect SD-WAN Orchestrator, affecting versions 9.6.2.x prior to 9.6.2.40210, 9.6.3.x prior to 9.6.3.40140, and 9.7.0.x prior to 9.7.0.43264. The flaws, tracked as CVE-2026-63455 and CVE-2026-63456, could allow an attacker to compromise data confidentiality and integrity and to bypass security policy controls on the SD-WAN orchestration platform.

HPE Aruba Networking published a corresponding security bulletin (HPESBNW05100) on 04 August 2026 detailing the fixed versions. No active exploitation is mentioned in the advisory; organizations running affected EdgeConnect SD-WAN Orchestrator deployments should apply the vendor-provided patches referenced in the bulletin.

Mentioned in this report

Vulnerabilities CVE-2026-63455CVE-2026-63456

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0969

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free