Multiples vulnérabilités dans les produits Netgate (14 août 2026)
Multiple vulnerabilities have been discovered in Netgate products, including pfSense. These vulnerabilities allow for data integrity compromise, data confidentiality breaches, and remote code execution. Several CVEs have been assigned, including CVE-2026-56126, CVE-2026-56127, CVE-2026-56128 and CVE-2026-67189. Users of pfSense CE and Plus versions prior to the specified release dates are at risk.
A series of security advisories released by CERT-FR detail multiple vulnerabilities within Netgate’s pfSense products. These vulnerabilities pose significant risks to system security and data integrity. Specifically, attackers could exploit these flaws to compromise data confidentiality and execute arbitrary code remotely. The vulnerabilities affect pfSense CE versions prior to 2.9.0 and pfSense Plus versions prior to 26.07.
CERT-FR has published a comprehensive list of security bulletins covering various versions of pfSense, each detailing specific vulnerabilities and recommended remediation steps. These bulletins include links to the corresponding downloads and CVE records. The identified vulnerabilities include remote code execution and cross-site scripting (XSS) attacks.
Key CVEs associated with this advisory include CVE-2026-56126, CVE-2026-56127, CVE-2026-56128 and CVE-2026-67189. Affected products include pfSense CE versions prior to 2.9.0 and pfSense Plus versions prior to 26.07. Users are strongly advised to update their pfSense installations to the latest stable version to mitigate these risks.