VORANT. Threat Intelligence Sign in Get the full feed

strongSwan patches multiple RCE, DoS flaws

routine vulnerability technologyinfrastructuretelecommunications

ANSSI advisory details multiple strongSwan vulnerabilities before 6.1.0 allowing remote code execution, denial of service, and security bypass.

ANSSI (CERT-FR) published an advisory covering multiple vulnerabilities affecting strongSwan versions prior to 6.1.0, an open-source IPsec-based VPN solution widely used on Linux, BSD, and other platforms. The vulnerabilities collectively allow a remote attacker to achieve arbitrary code execution, cause a denial of service, or bypass the software's security policy enforcement. No exploitation in the wild is mentioned in the advisory.

The advisory references eight new CVEs disclosed by strongSwan on 07 September 2026 (CVE-2026-78127, -78129 through -78135), along with two older CVEs (CVE-2014-2338 and CVE-2017-9023) included for reference. No technical details of the flaws are provided beyond the risk categories. Organizations running strongSwan for VPN/IPsec connectivity should consult the vendor's security bulletins and update to version 6.1.0 or later as soon as possible, particularly on internet-facing gateways where remote code execution or DoS could disrupt secure connectivity or allow policy bypass.

Mentioned in this report

Vulnerabilities CVE-2014-2338CVE-2017-9023CVE-2026-78127CVE-2026-78129CVE-2026-78130CVE-2026-78131CVE-2026-78132CVE-2026-78133CVE-2026-78134CVE-2026-78135

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1129

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free