CVE-2026-78123
strongSwan
Published 11 Sept 2026 · updated 15 Sept 2026 · Analyzed
5.9 Medium · CVSS 3.1, mitre.org
Description
strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin.
References
- github.com/strongswan/strongswan/releases/tag/6.1.0 · Patch, Release Notes, Vendor Advisory
- www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78123).html · Mitigation, Vendor Advisory