CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

[NEW] [high] Aruba EdgeConnect SD-WAN Orchestrator: Multiple Vulnerabilities Allow Bypass of Security Measures

highCVE-2026-63455CVE-2026-63456
A remote, anonymous attacker can exploit multiple vulnerabilities in Aruba EdgeConnect SD-WAN Orchestrator to bypass security measures, which can lead to disclosure of confidential information and manipulation of data.

CSIRTS triage

What
Multiple vulnerabilities allow remote unauthenticated attackers to bypass security measures and access confidential information or manipulate data.
Who is affected
Remote, unauthenticated attackers targeting any exposed instance of Aruba EdgeConnect SD-WAN Orchestrator.
Urgency
High priority; remote unauthenticated exploitation possible with direct security control bypass and data impact.
Action
Apply patches addressing CVE-2026-63455 and CVE-2026-63456 from Aruba immediately and review network exposure.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch EdgeConnect SD-WAN Orchestrator

Get an email when a new EdgeConnect SD-WAN Orchestrator advisory drops — max one per day, one-click unsubscribe.

Details

Source
CERT-Bund (BSI) Security Advisories (DE · national-cert · site)
Severity
high
Published
2026-08-05
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2661

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-63455coverage & exploitation statusNVD · CVE.org
CVE-2026-63456coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Aruba EdgeConnect SD-WAN Orchestrator

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from CERT-Bund (BSI) Security Advisories