news.mlab.sh
Back to the feed
vulnerability

Multiples vulnérabilités dans strongSwan (08 septembre 2026)

HighCVSS 7.5
Summary

Multiple vulnerabilities have been discovered in StrongSwan, a widely used VPN protocol implementation. These vulnerabilities allow for remote code execution, denial-of-service attacks, and bypassing security policies. Affected versions are prior to 6.1.0. Users should immediately update to a patched version to mitigate these risks.

Multiple vulnerabilities exist within the StrongSwan VPN implementation. These vulnerabilities, detailed in several security bulletins released on September 7, 2026, allow an attacker to potentially execute arbitrary code remotely, cause a denial-of-service attack, and circumvent security policies. The vulnerabilities are associated with CVE-2014-2338, CVE-2017-9023, CVE-2026-78127, CVE-2026-78129, CVE-2026-78130, CVE-2026-78131, CVE-2026-78132, CVE-2026-78133, CVE-2026-78134, and CVE-2026-78135. StrongSwan versions prior to 6.1.0 are affected. The CERT-FR has published security bulletins detailing these vulnerabilities and providing links to the corresponding updates. Users should update to a patched version of StrongSwan as soon as possible to address these security concerns.

Read the full article at CERT-FR