VORANT. Threat Intelligence Sign in Get the full feed

Stormshield SNS patches multiple RCE flaws

elevated vulnerability government-nationalinfrastructuredefense

Multiple vulnerabilities in Stormshield Network Security allow remote code execution, denial of service, and data disclosure; patches are available.

ANSSI (CERT-FR) published an advisory detailing multiple vulnerabilities affecting Stormshield Network Security (SNS), a widely deployed firewall/UTM product used by government and enterprise networks primarily in France and Europe. Affected versions span a broad range, including SNS 3.11.x through 4.3.x prior to 4.3.44, 4.8.x prior to 4.8.18, 5.0.x prior to 5.0.8, 5.1.x prior to 5.1.2, and versions prior to 3.7.45, indicating the flaws have persisted across several major release branches.

The vulnerabilities, tracked under nine separate CVE identifiers, collectively enable an attacker to achieve remote code execution, cause remote denial of service, or compromise data confidentiality. No public exploitation has been reported at this time; the advisory is a vendor-coordinated disclosure with corresponding Stormshield security bulletins (2026-013, 2026-014, 2026-015) providing patch guidance. Organizations running affected SNS versions should prioritize upgrading to the fixed releases referenced in the vendor bulletins.

Mentioned in this report

Vulnerabilities CVE-2026-25075CVE-2026-34180CVE-2026-35058CVE-2026-35328CVE-2026-35330pocCVE-2026-35332CVE-2026-40215CVE-2026-47895CVE-2026-7383

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1021

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free