{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3astrongswanstrongswan/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*"],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["strongSwan (\u003c 6.1.0)","strongSwan"],"_cs_severities":["high"],"_cs_tags":["vulnerability","network-security","patch-management"],"_cs_type":"advisory","_cs_vendors":["strongSwan"],"content_html":"\u003cp\u003eThe French National Cybersecurity Agency (ANSSI) has released an advisory regarding multiple critical vulnerabilities affecting the strongSwan IPsec VPN suite. These vulnerabilities, identified as CVE-2026-78127, CVE-2026-78129, CVE-2026-78130, CVE-2026-78131, CVE-2026-78132, CVE-2026-78133, CVE-2026-78134, and CVE-2026-78135, impact all versions of strongSwan prior to 6.1.0. Depending on the specific flaw, an unauthenticated remote attacker could potentially trigger arbitrary remote code execution, perform denial-of-service attacks, or bypass existing security policy configurations. Organizations utilizing strongSwan for secure network connectivity are advised to review the vendor-provided security bulletins and apply updates immediately. Given the nature of these vulnerabilities, the potential for service disruption or compromise of network security boundaries is high for internet-facing VPN gateways.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities can lead to full system compromise via remote code execution, persistent denial-of-service, or the subversion of network security policies. This poses a significant risk to organizations relying on strongSwan to secure sensitive data in transit, potentially allowing unauthorized access to internal network resources or the total loss of VPN gateway availability.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching all strongSwan instances to version 6.1.0 or later immediately. Refer to the official strongSwan security blog for specific remediation instructions for each CVE ID: CVE-2026-78127, CVE-2026-78129, CVE-2026-78130, CVE-2026-78131, CVE-2026-78132, CVE-2026-78133, CVE-2026-78134, and CVE-2026-78135.\u003c/p\u003e\n","date_modified":"2026-09-08T13:35:05Z","date_published":"2026-09-08T13:34:45Z","id":"https://feed.craftedsignal.io/briefs/2026-09-strongswan-vulnerabilities/","summary":"Multiple vulnerabilities, including remote code execution and security policy bypass, have been disclosed in strongSwan versions prior to 6.1.0.","title":"Multiple Vulnerabilities in strongSwan","url":"https://feed.craftedsignal.io/briefs/2026-09-strongswan-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}