StrongSwan is a technology platform tracked across 4 threat clusters and 5 intelligence report mentions on ThreatCluster. First observed November 3, 2025; most recent activity June 9, 2026.
StrongSwan is an open-source IPsec-based VPN platform used on Linux and other operating systems to provide site-to-site and remote-access VPN connectivity. It supports IKEv2/IKEv1, X.509 certificates, and PSK-based authentication, making it a common backbone for secure network tunnels; a high-severity vulnerability in this component can impact VPN gateways and remote access infrastructure, underscoring its significance in cybersecurity.
Recent updates for strongSwan, affecting SUSE and Ubuntu systems, have addressed several critical vulnerabilities. The issues include CVE-2026-35328, which can cause an infinite loop in TLS processing, and…
A critical vulnerability in strongSwan, identified as CVE-2026-25075, has been discovered, affecting Ubuntu 25.10, 24.04 LTS, and 22.04 LTS. The flaw, found by Kazuma Matsumoto, allows attackers to send specially…
A vulnerability in strongSwan, discovered by Elliott Childre, affects multiple Ubuntu releases, including 26.04 LTS, 25.10, 24.04 LTS, and 22.04 LTS. The flaw allows remote attackers to exploit specially crafted network…
SUSE and openSUSE have released updates for grub2 to address multiple vulnerabilities, including use-after-free and out-of-bounds write issues. The updates fix specific CVEs, including CVE-2025-54771 and CVE-2025-61661,…