CVE-2026-39312: Softether Softethervpn
High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.
SoftEtherVPN is a an open-source cross-platform multi-protocol VPN Program. In 5.2.5188 and earlier, a pre-authentication denial-of-service vulnerability exists in SoftEther VPN Developer Edition 5.2.5188 (and likely earlier versions of Developer Edition). An unauthenticated remote attacker can crash the vpnserver process by sending a single malformed EAP-TLS packet over raw L2TP (UDP/1701), terminating all active VPN sessions.
Affected products
- Softether Softethervpn: up to and including 5.2.5188
Published 2026-04-07. Last modified 2026-06-17.