strongSwan patches remote DoS flaw
CERT-FR advisory: strongSwan versions before 6.1.0 are vulnerable to a remote denial-of-service flaw (CVE-2026-78123); update to fix.
CERT-FR has published an advisory relaying a strongSwan security bulletin describing a remote denial-of-service vulnerability tracked as CVE-2026-78123. The flaw affects all strongSwan versions prior to 6.1.0, allowing a remote attacker to disrupt the IPsec/IKE service without authentication or user interaction, per the vendor advisory. No details on exploitation in the wild are provided in this bulletin.
Defenders running strongSwan for VPN/IPsec connectivity should identify affected instances and apply the vendor patch (upgrade to 6.1.0 or later) as referenced in the official strongSwan blog post. As this is a DoS-class vulnerability rather than one enabling code execution or data compromise, the operational impact is service availability rather than confidentiality or integrity, but any organization relying on strongSwan for critical VPN tunnels should prioritize patching to avoid connectivity disruption.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1180
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free