Multiple vulnerabilities in Stormshield Network Security (August 14, 2026)
Multiple vulnerabilities have been discovered in Stormshield Network Security. Some of them allow an attacker to cause remote arbitrary code execution, remote denial of service and data confidentiality breach.
CSIRTS triage
- What
- Multiple vulnerabilities in Stormshield Network Security enable remote code execution, denial of service, and data confidentiality breaches.
- Who is affected
- Stormshield Network Security appliances and systems running affected versions.
- Urgency
- Critical; remote code execution in a security appliance poses extreme risk and demands immediate patching.
- Action
- Apply security updates from Stormshield for the affected product versions without delay.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Stormshield Network Security
Get an email when a new Stormshield Network Security advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1021/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2026-341801.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 62% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-73830.80% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 55% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-250751.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 61% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-350580.54% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 44% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-478950.67% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 50% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-402150.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-35330 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-34180 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-35332 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-7383 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-25075 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-35328 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-35058 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-47895 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-40215 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [hoch] OpenSSL: Mehrere Schwachstellencert-bund
- medium[UPDATE] [mittel] OpenVPN: Mehrere Schwachstellencert-bund
- high[UPDATE] [high] strongSwan: Vulnerability enables code executioncert-bund
- highCVE-2026-47895: In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that…nvd
- unknownMultiple vulnerabilities in Splunk products (20 August 2026)cert-fr-avis
- high[NEW] [high] IBM App Connect Enterprise: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Solaris third-party components: Multiple vulnerabilitiescert-bund
- highCVE-2026-47895: In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that…msrc
- highCVE-2026-34180: Heap Buffer Over-read in ASN.1 Content Parsingmsrc
- highCVE-2026-7383: Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversionmsrc
- unknownMultiple vulnerabilities in IBM products (July 24, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in Oracle Database Server (July 23, 2026)cert-fr-avis
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans les produits Palo Alto Networks (10 septembre 2026)2026-09-10
- unknownVulnérabilité dans Laravel (10 septembre 2026)2026-09-10
- unknownMultiples vulnérabilités dans les produits Veeam (10 septembre 2026)2026-09-10
- unknownVulnérabilité dans Apereo CAS (10 septembre 2026)2026-09-10
- unknownMultiples vulnérabilités dans HPE Aruba Networking ClearPass Policy Manager (10 septembre 2026)2026-09-10