Skip to content
Threat Feed
high advisory

Multiple Vulnerabilities in strongSwan

Multiple vulnerabilities, including remote code execution and security policy bypass, have been disclosed in strongSwan versions prior to 6.1.0.

What's new

  • 1. new product Sep 8, 13:35 via bsi

The French National Cybersecurity Agency (ANSSI) has released an advisory regarding multiple critical vulnerabilities affecting the strongSwan IPsec VPN suite. These vulnerabilities, identified as CVE-2026-78127, CVE-2026-78129, CVE-2026-78130, CVE-2026-78131, CVE-2026-78132, CVE-2026-78133, CVE-2026-78134, and CVE-2026-78135, impact all versions of strongSwan prior to 6.1.0. Depending on the specific flaw, an unauthenticated remote attacker could potentially trigger arbitrary remote code execution, perform denial-of-service attacks, or bypass existing security policy configurations. Organizations utilizing strongSwan for secure network connectivity are advised to review the vendor-provided security bulletins and apply updates immediately. Given the nature of these vulnerabilities, the potential for service disruption or compromise of network security boundaries is high for internet-facing VPN gateways.

Impact

Successful exploitation of these vulnerabilities can lead to full system compromise via remote code execution, persistent denial-of-service, or the subversion of network security policies. This poses a significant risk to organizations relying on strongSwan to secure sensitive data in transit, potentially allowing unauthorized access to internal network resources or the total loss of VPN gateway availability.

Recommendation

Prioritize patching all strongSwan instances to version 6.1.0 or later immediately. Refer to the official strongSwan security blog for specific remediation instructions for each CVE ID: CVE-2026-78127, CVE-2026-78129, CVE-2026-78130, CVE-2026-78131, CVE-2026-78132, CVE-2026-78133, CVE-2026-78134, and CVE-2026-78135.


Immediate actions

Upgrade all instances of strongSwan to 6.1.0 or later

IT Operations 24h

Mitigations

Patching to 6.1.0

immediate IT Operations

CVE-2026-78127 through CVE-2026-78135