
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-78133 is a use-after-free vulnerability in strongSwan's libcharon library, triggered during IKEv2 rekeying collision handling, which can potentially lead to remote code execution. The CVE was reserved and first indexed by Feedly on September 7, 2026, with a Debian security advisory published shortly after. Affected software is strongSwan (vendor: strongswan), though specific version ranges have not yet been publicly detailed. The estimated CVSS severity is Medium (Feedly, Debian Advisory).
The root cause is a use-after-free condition (CWE-416) in libcharon, the core IKE daemon library in strongSwan, occurring when two IKEv2 rekeying operations collide — a known edge case in the IKEv2 protocol where both peers simultaneously initiate rekeying of the same SA. This race condition can cause a memory object to be freed and subsequently accessed, potentially allowing an attacker to corrupt heap memory. Exploitation would require the ability to participate in or influence IKEv2 session rekeying, which may be achievable by a network-adjacent or remote attacker depending on the deployment. Nessus detection plugins 343484 and 343509 have been published to identify vulnerable systems (Feedly, Tenable Plugin 343484, Tenable Plugin 343509).
Successful exploitation of this use-after-free vulnerability could allow a remote attacker to execute arbitrary code in the context of the strongSwan IKE daemon, which typically runs with elevated privileges. This could result in full compromise of the VPN gateway, enabling interception or manipulation of VPN traffic, lateral movement into protected network segments, and potential exposure of sensitive credentials or data traversing the VPN tunnel. Availability impact is also significant, as exploitation may crash the IKE daemon, disrupting VPN connectivity (Feedly, Debian Advisory).
As of the time of this report, no public proof-of-concept exploit code has been identified, and there is no confirmed evidence of in-the-wild exploitation (Feedly). The CVE status remains "Reserved" with limited published technical detail, and it has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. EPSS score data is not yet available. The vulnerability's exploitability is constrained by the requirement to trigger an IKEv2 rekeying collision, which may require a man-in-the-middle position or control over a peer VPN endpoint.
Users should apply the patches distributed via the Debian security advisory (DSA) for strongSwan as soon as possible, upgrading to the fixed package version referenced in the advisory (Debian Advisory). Organizations running strongSwan on other Linux distributions should monitor their respective vendor channels for updated packages. As a temporary workaround, consider restricting IKEv2 rekeying intervals or disabling rekeying where operationally feasible, and limit exposure of IKE endpoints to trusted peers only. Use Nessus plugins 343484 and 343509 to scan for vulnerable instances (Tenable Plugin 343484, Tenable Plugin 343509).
The vulnerability received coverage in the German Linux security community via Pro-Linux.de, which reported on multiple strongSwan issues (Pro-Linux). AusCERT published a bulletin (ESB-2026.10585) alerting its constituency (AusCERT). LinuxCompatible.org included it in a daily security roundup covering patches across major distributions (LinuxCompatible). No notable individual researcher commentary or significant social media discussion has been identified at this time.
Fix availability across major Linux distributions and their releases.
bionic (esm-infra)
strongswan
bionic (fips-updates)
strongswan
bionic (fips)
strongswan
devel
strongswan: 6.0.7-1ubuntu3
focal (esm-infra)
strongswan
focal (fips-updates)
strongswan
focal (fips)
strongswan
jammy
strongswan
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."