rootpwn

Advisories

Netgate pfSense Remote Code Execution Vulnerability (Sept 16 2026)

A critical flaw in Netgate’s pfSense firewall software allows attackers to run arbitrary code remotely. The issue affects all pfSense CE releases older than 2.9.0 and all pfSense Plus builds before 26.07. The vulnerability was disclosed by the French CERT (CERT‑FR) and a patch is available in the Netgate Security Advisory SA‑26_22. Administrators should update immediately to mitigate the risk of compromise.

What’s at stake?

A newly uncovered flaw in Netgate pfSense can be exploited from outside the network, giving an attacker full control over the affected device. The weakness lies in the way pfSense handles certain configuration requests, allowing arbitrary code execution without authentication.

Systems impacted

  • pfSense CE – any version prior to 2.9.0
  • pfSense Plus – any build before 26.07

How to protect yourself

Download the latest patch from Netgate’s official advisory (SA‑26_22, released 15 September 2026) and apply it to all vulnerable installations. Verify that the firmware version is at least 2.9.0 for CE or 26.07 for Plus before proceeding.

"The vulnerability is exploitable by unauthenticated remote actors. Prompt remediation is essential to prevent potential takeover of your network perimeter."

Next steps for administrators

  • Check current pfSense version via the webGUI or CLI.
  • Download the patch from the Netgate website (no need for additional credentials).
  • Apply the update in a maintenance window and reboot the device.
  • Validate the new version and monitor logs for any suspicious activity.

Netgate pfSense Remote Code Execution CERT-FR Security Advisory

← All news