CVE-2025-11955: Thegreenbow VPN Client Windows Enterprise

High severity, CVSS 8.2. EPSS: 0.2% chance of exploitation in the next 30 days.

Incorrect validation of OCSP certificates vulnerability in TheGreenBow VPN, versions 7.5 and 7.6. During the IKEv2 authentication step, the OCSP-enabled VPN client establishes the tunnel even if it does not receive an OCSP response or if the OCSP response signature is invalid.

Affected products

  • Thegreenbow Thegreenbow VPN Client Windows Enterprise: version 7.5 only; version 7.6 only

Published 2025-10-27. Last modified 2026-10-08.