← Vulnerability feed

Vulnerability record · CVE-2026-78135 · published 11 September 2026

CVE-2026-78135: Strongswan vulnerability

Strongswan · Strongswan

libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass.

7.3 CVSS 3.1 High EPSS 0.36% · top 72.5% CWE-841 · CWE-841
7.3CVSS 3.1 base score
0.36%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
16 Sep 2026Last modified by NVD

Description

libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-78135 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2004-0590Frees wan vulnerabilityFreeS/WAN 1.x and 2.x, and other related products including superfreeswan 1.x, openswan 1.x before 1.0.6, openswan 2.x before 2.1.4, and strongSwan b…EPSS 2.8%9.8CVE-2023-41913Strongswan classic buffer overflow vulnerabilitystrongSwan before 5.9.12 has a buffer overflow and possible unauthenticated remote code execution via a DH public value that exceeds the internal buf…EPSS 2.3%9.8CVE-2023-26463Strongswan improper certificate validation vulnerabilitystrongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two different purposes within the s…EPSS 2.3%9.8CVE-2015-3991Strongswan vulnerabilitystrongSwan 5.2.2 and 5.3.0 allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code.EPSS 4.6%9.1CVE-2021-45079Strongswan null pointer dereference vulnerabilityIn strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the ca…EPSS 2.8%7.5CVE-2026-78130Strongswan null pointer dereference vulnerabilitystrongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.EPSS 0.32%7.5CVE-2026-78132Strongswan vulnerabilitystrongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parser for ietfAttrSyntax.EPSS 0.32%7.5CVE-2026-78133Strongswan use after free vulnerabilitylibcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling.EPSS 0.43%

Source: NIST National Vulnerability Database (record CVE-2026-78135), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.