libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass.
CVE-2026-78135
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
Review the complete instructions on the vendor's siteThe publication date reported by the vendor.
We collected the advisory from the official source.