# Aruba EdgeConnect SD-WAN Orchestrator flaws patched

Published: 2026-08-05 · Severity: medium · Sectors: telecommunications, infrastructure
Canonical: https://vorant.io/reports/01276f81-0fb9-51ee-a57d-999a94654cc4/aruba-edgeconnect-sd-wan-orchestrator-flaws-patched

> HPE Aruba Networking patched two vulnerabilities in EdgeConnect SD-WAN Orchestrator that could allow data confidentiality/integrity breaches and security policy bypass.

CERT-FR issued an advisory covering multiple vulnerabilities in HPE Aruba Networking's EdgeConnect SD-WAN Orchestrator, affecting versions 9.6.2.x prior to 9.6.2.40210, 9.6.3.x prior to 9.6.3.40140, and 9.7.0.x prior to 9.7.0.43264. The flaws, tracked as CVE-2026-63455 and CVE-2026-63456, could allow an attacker to compromise data confidentiality and integrity and to bypass security policy controls on the SD-WAN orchestration platform.

HPE Aruba Networking published a corresponding security bulletin (HPESBNW05100) on 04 August 2026 detailing the fixed versions. No active exploitation is mentioned in the advisory; organizations running affected EdgeConnect SD-WAN Orchestrator deployments should apply the vendor-provided patches referenced in the bulletin.

## Mentioned in this report

- Vulnerabilities: CVE-2026-63455, CVE-2026-63456

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0969

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/01276f81-0fb9-51ee-a57d-999a94654cc4/aruba-edgeconnect-sd-wan-orchestrator-flaws-patched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
