HPE Aruba Networking has addressed two critical security vulnerabilities (CVE-2026-63455 and CVE-2026-63456) in its EdgeConnect SD-WAN Orchestrator, both assigned a CVSS score of 9.8. These vulnerabilities allow unauthenticated remote attackers to bypass web authentication via spoofed HTTP headers, potentially enabling access to sensitive information. As of now, there have been no confirmed exploitations. Affected versions include the 9.6.x branch, with recommended patches available in newer builds. HPE recommends immediate upgrades and additional security measures while affected systems remain unpatched.
CVE-2026-63455: EdgeConnect Orchestrator Web Authentication Bypass Rated CVSS 9.8
CyberSIXT Evidence Panel
Article by CyberSIXT