Stormshield Management Center patches five vulnerabilities
Stormshield patched five vulnerabilities in Management Center versions before 3.9.2 enabling arbitrary code execution and data compromise.
France's CERT has issued an advisory for multiple vulnerabilities discovered in Stormshield Management Center affecting all versions prior to 3.9.2. The vulnerabilities, tracked as CVE-2026-6473, CVE-2026-6475, CVE-2026-6477, CVE-2026-6637, and CVE-2026-6638, allow attackers to execute arbitrary code, compromise data confidentiality, and compromise data integrity.
Stormshield Management Center is a centralized management platform for Stormshield network security appliances, commonly deployed in enterprise and government environments. The advisory references Stormshield security bulletin 2026-012 released on June 29, 2026, which contains patches and remediation guidance.
No active exploitation or threat actor attribution is mentioned in the advisory. Organizations running affected versions should consult the vendor bulletin and apply the available patches to version 3.9.2 or later.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0816/
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free