StrongSwan — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
November 3, 2025
Last Seen
June 9, 2026

StrongSwan is a technology platform tracked across 4 threat clusters and 5 intelligence report mentions on ThreatCluster. First observed November 3, 2025; most recent activity June 9, 2026.

Overview

StrongSwan is an open-source IPsec-based VPN platform used on Linux and other operating systems to provide site-to-site and remote-access VPN connectivity. It supports IKEv2/IKEv1, X.509 certificates, and PSK-based authentication, making it a common backbone for secure network tunnels; a high-severity vulnerability in this component can impact VPN gateways and remote access infrastructure, underscoring its significance in cybersecurity.

Related Threat Clusters

Recent Intelligence Reports

  • Ubuntu 26.04 LTS strongSwan Critical DoS Risk USN-8407 — Linuxsecurity · June 9, 2026
  • USN-8407-1: strongSwan vulnerability — Ubuntu · June 8, 2026
  • Ubuntu 26.04 LTS strongSwan Advisory USN-8196-2 CVE-2026 — Linuxsecurity · April 27, 2026
  • Ubuntu 25.10 strongSwan Critical DoS Exploit USN-8117-1 CVE-2026 — Linuxsecurity · March 23, 2026
  • SUSE Linux 12 SP5: StrongSwan Important Buffer Overflow CVE-2025 — Linuxsecurity · November 3, 2025

CVSS v3.1 Breakdown