SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-76680

HIGH · CVSS 8.5 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The EdgeConnect SD-WAN Orchestrator's API is vulnerable to server-side request forgery (SSRF) attacks, which can be exploited by remote attackers with low-level authentication. Successful exploitation may allow attackers to gather sensitive information about the internal architecture of the system, potentially leading to unauthorized data disclosure. Organizations using EdgeConnect SD-WAN Orchestrator should prioritize addressing this vulnerability to safeguard their internal data and infrastructure.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-76680
Severity
HIGH
CVSS
8.5
EPSS
0.29%

Original NVD Description

Vulnerabilities in the API of EdgeConnect SD-WAN Orchestrator could allow a remote attacker authenticated with low privileges to conduct server-side request forgery (SSRF) attacks. A successful exploit allows an attacker to enumerate information about the internal structure of the EdgeConnect SD-WAN Orchestrator host leading to potential disclosure of sensitive information beyond what is authorized by the user's existing privilege level.