# strongSwan patches remote DoS flaw

Published: 2026-09-16 · Severity: routine
Canonical: https://vorant.io/reports/8a605be5-1f5f-5a5f-9e7f-233500c40943/strongswan-patches-remote-dos-flaw

> CERT-FR advisory: strongSwan versions before 6.1.0 are vulnerable to a remote denial-of-service flaw (CVE-2026-78123); update to fix.

CERT-FR has published an advisory relaying a strongSwan security bulletin describing a remote denial-of-service vulnerability tracked as CVE-2026-78123. The flaw affects all strongSwan versions prior to 6.1.0, allowing a remote attacker to disrupt the IPsec/IKE service without authentication or user interaction, per the vendor advisory. No details on exploitation in the wild are provided in this bulletin.

Defenders running strongSwan for VPN/IPsec connectivity should identify affected instances and apply the vendor patch (upgrade to 6.1.0 or later) as referenced in the official strongSwan blog post. As this is a DoS-class vulnerability rather than one enabling code execution or data compromise, the operational impact is service availability rather than confidentiality or integrity, but any organization relying on strongSwan for critical VPN tunnels should prioritize patching to avoid connectivity disruption.

## Mentioned in this report

- Vulnerabilities: CVE-2026-78123

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1180

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/8a605be5-1f5f-5a5f-9e7f-233500c40943/strongswan-patches-remote-dos-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
