Stormshield SNS data leak flaw patched
A confidentiality vulnerability in Stormshield Network Security versions prior to 5.0.6 allows attackers to access sensitive data.
CERT-FR has issued an advisory for a vulnerability in Stormshield Network Security (SNS) that poses a risk to data confidentiality. The flaw, tracked as CVE-2026-31790, affects all SNS 5.x versions prior to 5.0.6.
The vulnerability allows an attacker to compromise the confidentiality of data on affected systems. While the advisory does not provide detailed exploitation mechanics or evidence of active exploitation, organizations running vulnerable versions are advised to apply available patches.
Stormshield has released version 5.0.6 to address the issue. Organizations should consult the vendor's security bulletin 2026-011 published on June 9, 2026, for patch details and deployment guidance.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0723
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free