[NEU] [hoch] strongSwan: Mehrere Schwachstellen
Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in strongSwan ausnutzen, um einen Denial of Service zu verursachen, Sicherheitsmaßnahmen zu umgehen, Informationen offenzulegen und Code auszuführen.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3230
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-78123 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-78124 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-78126 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-78127 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-78129 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-78130 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-78131 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-78132 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-78133 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-78134 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-78135 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMultiples vulnérabilités dans strongSwan (08 septembre 2026)cert-fr-avis
- unknownDSA-6487-1 strongswan - security updatedebian
Recent advisories for strongSwan
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownMultiples vulnérabilités dans strongSwan (08 septembre 2026)cert-fr-avis · 2026-09-08
- unknownDSA-6487-1 strongswan - security updatedebian · 2026-09-07
- high[UPDATE] [high] strongSwan: Vulnerability enables code executioncert-bund · 2026-08-24
- highCVE-2026-47895: In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that…nvd · 2026-08-22
- highCVE-2026-47895: In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that…msrc · 2026-08-11
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [mittel] OpenSSH: Mehrere Schwachstellen2026-09-10
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen2026-09-10
- high[UPDATE] [hoch] OpenVPN: Mehrere Schwachstellen2026-09-10
- medium[UPDATE] [mittel] gzip: Mehrere Schwachstellen2026-09-10
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen2026-09-10