CVE-2026-76680

Vulnerabilities in the API of EdgeConnect SD-WAN Orchestrator could allow a remote attacker authenticated with low privileges to conduct server-side request forgery (SSRF) attacks. A successful exploit allows an attacker to enumerate information about the internal structure of the EdgeConnect SD-WAN Orchestrator host leading to potential disclosure of sensitive information beyond what is authorized by the user's existing privilege level.

  • Published Sep 15, 2026
  • CVSS 8.5 high
  • 0.4% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-76680 at the National Vulnerability Database