strongSwan RCE flaw CVE-2026-47895 patched
A remote code execution vulnerability in strongSwan versions before 6.0.7 allows attackers to execute arbitrary code remotely.
The French national cybersecurity agency ANSSI has issued an advisory for CVE-2026-47895, a vulnerability affecting strongSwan VPN software prior to version 6.0.7. The flaw enables remote attackers to execute arbitrary code on vulnerable systems.
strongSwan is widely deployed open-source IPsec-based VPN software used across enterprise and government networks. The vendor released version 6.0.7 to address this vulnerability on June 8, 2026.
Organizations running affected versions should prioritize patching given the remote exploitability and potential for full system compromise. No additional technical details about exploitation techniques or active exploitation have been disclosed in the advisory.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0709
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free