Multiple vulnerabilities in Stormshield Network Security (August 14, 2026)
Multiple vulnerabilities have been discovered in Stormshield Network Security. Some of them allow an attacker to cause remote arbitrary code execution, remote denial of service and data confidentiality breach.
CSIRTS triage
- What
- Multiple vulnerabilities in Stormshield Network Security enable remote code execution, denial of service, and data confidentiality breaches.
- Who is affected
- Stormshield Network Security appliances and systems running affected versions.
- Urgency
- Critical; remote code execution in a security appliance poses extreme risk and demands immediate patching.
- Action
- Apply security updates from Stormshield for the affected product versions without delay.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Stormshield Network Security
Get an email when a new Stormshield Network Security advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1021/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2026-341801.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 61% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-73830.63% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 47% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-250751.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 60% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-350580.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-402150.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-35330 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-34180 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-35332 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-7383 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-25075 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-35328 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-35058 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-47895 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-40215 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[UPDATE] [medium] OpenVPN: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Solaris third-party components: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] OpenSSL: Multiple Vulnerabilitiescert-bund
- highCVE-2026-7383: Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversionmsrc
- highCVE-2026-34180: Heap Buffer Over-read in ASN.1 Content Parsingmsrc
- unknownMultiple vulnerabilities in IBM products (July 24, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in Oracle Database Server (July 23, 2026)cert-fr-avis
- high[NEW] [high] Oracle Database Server: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Tenable Identity Exposure (June 24, 2026)cert-fr-avis
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Debian Linux kernel (August 14, 2026)2026-08-14
- unknownMultiple vulnerabilities in Elastic Kibana (August 14, 2026)2026-08-14
- unknownMultiple vulnerabilities in Netgate products (August 14, 2026)2026-08-14
- unknownMultiple vulnerabilities in SUSE Linux kernel (August 14, 2026)2026-08-14
- unknownVulnerability in Sophos products (August 14, 2026)2026-08-14