VORANT. Threat Intelligence Sign in Get the full feed

Multiple vulnerabilities in FreeRadius 3.0.x and 3.2.x enable

high vulnerability telecommunicationstechnologyinfrastructure

Multiple vulnerabilities in FreeRadius 3.0.x and 3.2.x enable remote denial of service, data confidentiality breaches, and unspecified security issues.

The French CERT (ANSSI) has issued an advisory regarding multiple security vulnerabilities discovered in FreeRadius, an open-source RADIUS server implementation. The vulnerabilities affect FreeRadius versions 3.2.x prior to 3.2.9 and versions 3.0.x prior to 3.0.28. According to the advisory, these flaws allow attackers to remotely trigger denial of service conditions, compromise the confidentiality of data, and exploit additional security weaknesses not yet detailed by the vendor.

FreeRadius is widely deployed in enterprise and service provider environments for network authentication, authorization, and accounting (AAA) functions. The affected versions handle critical authentication flows for wireless networks, VPN access, and network access control systems. Organizations using vulnerable versions should prioritize patching, as exploitation could enable unauthorized access or service disruption.

The vendor has released patches in versions 3.0.28 and 3.2.9 to address these issues. Given the role FreeRadius plays in authentication infrastructure and the remote exploitability of at least some vulnerabilities, organizations should treat this as a high-priority update cycle, particularly for internet-facing or high-value authentication servers.

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0688

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free