CVE-2026-25075Disclosure

MEDIUMCVSS 8.7 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allows unauthenticated remote attackers to cause a denial of service by sending crafted AVP data with invalid length fields during IKEv2 authentication. Attackers can exploit the failure to validate AVP length fields before subtraction to trigger excessive memory allocation or NULL pointer dereference, crashing the charon IKE daemon.

5.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-191CWE-476

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 14 mentions across 12 observed days

What's happening

  • Active exploitation reported across 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 11 signals
  • Disclosure: 7 classified signals
  • General: 2 classified signals
  • Peaked 8d ago at 2 mentions (2026-03-27); latest day: 1
  • 14 total mentions across 12 days

Deep dive

Activity timeline14 mentions / 12d
01122Mentions · 2026-03-23: 1Mentions · 2026-03-24: 1Mentions · 2026-03-26: 1Mentions · 2026-03-27: 2Mentions · 2026-03-28: 1Mentions · 2026-03-29: 1Mentions · 2026-03-31: 1Mentions · 2026-04-01: 2Mentions · 2026-04-02: 1Mentions · 2026-04-03: 1Mentions · 2026-04-12: 1Mentions · 2026-04-18: 1PoC Mentioned / Linked · 2026-03-23: 1PoC Mentioned / Linked · 2026-04-01: 1Active Exploitation · 2026-03-31: 1Active Exploitation · 2026-04-02: 1Patch / Workaround · 2026-03-26: 1Patch / Workaround · 2026-03-29: 1Patch / Workaround · 2026-04-01: 1Patch / Workaround · 2026-04-02: 1Patch / Workaround · 2026-04-03: 1Patch / Workaround · 2026-04-18: 1Technical Details · 2026-03-24: 1Technical Details · 2026-03-26: 1Technical Details · 2026-03-27: 2Technical Details · 2026-03-28: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-01: 2Technical Details · 2026-04-02: 1Technical Details · 2026-04-03: 1Technical Details · 2026-04-18: 103-2303-2403-2603-2703-2803-2903-3104-0104-0204-0304-1204-18
Signal classification4 categories
Disclosure
750.0%
Patch
428.6%
General
214.3%
Active Exploitation
17.1%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-03-231
Disclosure1
2026-03-241
Disclosure1
2026-03-261
Patch1
2026-03-272
Disclosure1General1
2026-03-281
Disclosure1
2026-03-291
Patch1
2026-03-311
Active Exploitation1
2026-04-012
Disclosure1Patch1
2026-04-021
Patch1
2026-04-031
Disclosure1
2026-04-121
General1
2026-04-181
Disclosure1
Full discourse14 posts
  • Gray Hats@the_yellow_fall
    Patch

    strongSwan fixes a high-severity DoS flaw (CVE-2026-25075) in eap-ttls. Unauthenticated actors can crash VPN gateways. Patch now to stay protected! #strongSwan #VPN #CyberSecurity #InfoSec #PatchAlert #NetworkSecurity #DoS #Vulnerability #CVE #IPsec https://securityonline.info/strongswan-vpn-cve-2026-25075-eap-ttls-dos-vulnerability/ https://t.co/i7le1Vpdal

    Post summary

    The post advertises a patch for a high‑severity DoS vulnerability (CVE‑2026‑25075) in strongSwan’s eap‑ttls, urging users to apply the fix; no misuse or exploit details are provided.

    050103639
    10.9K followersView on X
  • Misbar | مسبار@MisbarSec
    Patch

    📌 استغلال ثغرة قديمة في strongSwan لتعطيل خدمات VPN عبر Integer Underflow تكشف الأبحاث عن ثغرة حرجة (CVE-2026-25075 و CVE-2025-31324) موجودة منذ 15 عامًا في إضافة EAP-TTLS ضمن برنامج strongSwan. تستغل هذه الثغرة خطأً حسابيًا من نوع "Integer Underflow" لإحداث فساد هائل في الذاكرة. يتيح هذا الاستغلال للمهاجمين تعطيل خدمات شبكات VPN (Virtual Private Networks) وإسقاطها، مما يؤدي إلى حرمان من الخدمة (Denial of Service). يُنصح بالتحديث الفوري لـ strongSwan لمعالجة هذه الثغرة وتجنب الانقطاعات المحتملة للخدمة. 🔗 للمزيد: https://hackread.com/strongswan-flaw-attackers-crash-vpn-integer-underflow/ #العربي_بلس #الامن_السيبراني #تقنية

    Post summary

    The post reveals a long‑standing integer underflow flaw in strongSwan’s EAP‑TTLS, reports potential denial‑of‑service impacts, and urges users to promptly patch their installations.

    0003044
    245 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Disclosure

    A 15-year-old integer underflow in strongSwan’s EAP-TTLS plugin (CVE-2026-25075) causes massive heap corruption, allowing attackers to crash VPNs via impossible memory allocations. Affects versions 4.5.0 to 6.0.4. #strongSwan #VPNFlaw #Germany https://ift.tt/EB0vWkg

    Post summary

    StrongSwan’s EAP‑TTLS plugin has a long‑standing integer underflow that causes heap corruption and VPN crashes; affected versions are 4.5.0 through 6.0.4, though no exploit, patch, or PoC details are provided.

    00010141
    3.9K followersView on X
  • Sami Laiho@samilaiho
    General

    strongSwan CVE-2026-25075: Integer Underflow in VPN Authentication https://bishopfox.com/blog/strongswan-cve-2026-25075-integer-underflow-in-vpn-authentication

    Post summary

    The text announces the discovery of an integer underflow vulnerability in strongSwan VPN authentication, providing limited technical detail but no PoC, exploit, active use, or patch information.

    00010668
    30.4K followersView on X
  • Turki Alsalem@nexorify
    Disclosure

    ثغرة خطيرة بـ strongSwan VPN (CVE-2026-25075). تأثر كل الإصدارات من 4.5.0 لـ 6.0.4. النتيجة: الهاكر يقدر يعطّل خدمة VPN كاملة عن طريق integer underflow. إذا شركتك تستخدم strongSwan — حدّث فوراً. الـ VPN اللي تثق فيه ممكن يكون أضعف نقطة عندك. #Cybersecurity

    Post summary

    A new integer underflow vulnerability (CVE‑2026‑25075) affecting strongSwan VPN versions 4.5.0‑6.0.4 can disable the service; all users are urged to update immediately.

    0000039
    4 followersView on X
  • Polsia@polsia
    General

    CVE-2026-25075 hits strongSwan. Weaponized in hours. Your team sees Friday. ThreatForge sees Tuesday. That gap is where breaches happen. Intelligence wins when it arrives before the exploit does. https://threatforge-l929.polsia.app

    Post summary

    The tweet briefly announces CVE‑2026‑25075 against strongSwan and emphasizes the importance of timely intelligence to preclude exploitation, but it lacks technical details, PoC references, or evidence of active attacks.

    0000042
    13.8K followersView on X
  • TheDarkForge@DarkForgeNews
    Disclosure

    [CYBERSEC] 𝘀𝘁𝗿𝗼𝗻𝗴𝗦𝘄𝗮𝗻 𝗘𝗔𝗣-𝗧𝗧𝗟𝗦 𝗙𝗹𝗮𝘄 𝗘𝗻𝗮𝗯𝗹𝗲𝘀 𝗩𝗣𝗡 𝗗𝗲𝗻𝗶𝗮𝗹 𝗼𝗳 𝗦𝗲𝗿𝘃𝗶𝗰𝗲 Bishop Fox disclosed CVE-2026-25075, a CVSS 7.5 integer underflow in strongSwan's EAP-TTLS plugin affecting all versions from 4.5.0 through 6.0.4—spanning 15 years of releases. The flaw allows unauthenticated remote attackers to trigger unbounded memory allocations, crashing the IKE daemon. strongSwan 6.0.5 contains the fix. — 𝗧𝗛𝗘 𝗙𝗢𝗥𝗚𝗘'𝗦 𝗪𝗘𝗜𝗚𝗛𝗧 How can a vulnerability remain undetected for fifteen years in a critical infrastructure component? What steps must be taken to ensure such gaps are closed before exploitation becomes widespread? 𝘚𝘰𝘶𝘳𝘤𝘦𝘴: 𝘉𝘪𝘴𝘩𝘰𝘱 𝘍𝘰𝘹 | 𝘴𝘵𝘳𝘰𝘯𝘨𝘚𝘸𝘢𝘯 𝘗𝘳𝘰𝘫𝘦𝘤𝘵 | 𝘕𝘝𝘋

    Post summary

    Bishop Fox announced CVE‑2026‑25075, an integer underflow that can crash strongSwan’s IKE daemon, and noted that version 6.0.5 contains the fix.

    0000038
    18 followersView on X
  • CybrPulse@CybrPulse
    Patch

    CVE-2026-25075 in strongSwan: present since v4.5.0 (2011). Unauthenticated crash of the IKE daemon via crafted EAP-TTLS message. No auth required. Multiple reports hitting our feeds this week. Patch: 6.0.5. Check for embedded instances in appliances.

    Post summary

    CVE-2026-25075 is an unauthenticated crash vulnerability in strongSwan’s IKE daemon triggered by crafted EAP‑TTLS messages; a patch (6.0.5) is available, and recent reports suggest the issue is being actively exploited.

    0000038
    24 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting CVE-2026-25075 can crash strongSwan VPN servers remotely without authentication. Crafted EAP-TTLS messages trigger integer underflow, causing denial of service that blocks legitimate user connections. #Vulnerability 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/strongswan-2026-integer-underflow-vulnerability

    Post summary

    Attackers are actively exploiting CVE-2026-25075 in strongSwan VPN servers via crafted EAP‑TTLS messages, causing a remote denial of service that blocks legitimate users.

    0000040
    1.9K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Essential reading for infrastructure teams: Our comprehensive pillar page on strongSwan CVE-2026-25075 covers technical remediation, compliance mapping, and ROI analysis for enterprise VPN security. Read more: 👉 https://tinyurl.com/mtfkbh4e #Security #Mageia https://t.co/kZnB5VPTFD

    Post summary

    The tweet promotes a pillar page that outlines remediation steps for strongSwan CVE‑2026‑25075, including compliance and ROI considerations, but does not provide a PoC, exploit code, or evidence of active exploitation.

    0000052
    1.5K followersView on X
  • CrowdCyber 🌐@CrowdCyber_Com
    Disclosure

    High-Severity strongSwan Flaw Enables Remote VPN Gateway Crashes https://securityonline.info/strongswan-vpn-cve-2026-25075-eap-ttls-dos-vulnerability/

    Post summary

    A high‑severity vulnerability in strongSwan has been disclosed that permits remote attackers to crash VPN gateways, but no proof‑of‑concept, exploit code, active exploitation, or patch is mentioned.

    0000037
    243 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『Kazuma Matsumoto reported a bug in the eap-ttls plugin related to handling EAP-TTLS AVPs that can lead to resource exhaustion or a crash.』 strongSwan Vulnerability (CVE-2026-25075) https://www.strongswan.org/blog/2026/03/23/strongswan-vulnerability-(cve-2026-25075).html

    Post summary

    A new vulnerability (CVE‑2026‑25075) affecting the strongSwan eap‑ttls plugin has been disclosed, potentially allowing resource exhaustion or crash via malformed AVP handling.

    00000282
    6.8K followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    BREAKING: Critical DoS flaw CVE-2026-25075 in strongSwan hits Ubuntu 25.10, 24.04 LTS and 22.04 LTS, allowing crafted traffic to crash VPN services until systems are updated. https://threatcluster.io/cluster/critical-dos-vulnerability-in-strongswan-affects-multiple-ub-470eb824

    Post summary

    Critical DoS flaw CVE-2026-25075 in strongSwan hits multiple Ubuntu releases, allowing crafted traffic to crash VPN services; systems must be updated to mitigate the risk.

    0000051
    113 followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-25075 - strongSwan - strongSwan - https://www.redpacketsecurity.com/cve-alert-cve-2026-25075-strongswan-strongswan/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-25075 #strongswan #

    Post summary

    The tweet announces the CVE-2026-25075 vulnerability in strongSwan and directs readers to a CVE alert page for further details.

    00000102
    3.6K followersView on X

Explore more