CVE-2026-38961: XSS

Published Sep 4, 2026
·
Updated

Cross-Site Scripting (XSS) vulnerability in the RSS Widget of Netgate pfSense Plus (versions 26.03, 25.11.1) and pfSense CE (version 2.8.1) allows remote authenticated attackers to inject arbitrary JavaScript via malicious content in an RSS feed title. The injected script executes in the browser of any authenticated user who views the dashboard, due to insufficient sanitization of feed title data before rendering in the widget.

Affected Software

2 affected components
Netgate pfSense Plus>=25.11.1<=26.03
Netgate pfSense CE=2.8.1

Event History

Sep 4, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description

Frequently Asked Questions

1

Who is exposed to this issue?

Administrators or other authenticated users who view a pfSense dashboard containing the RSS Widget are exposed. The issue affects pfSense Plus 26.03 and 25.11.1, and pfSense CE 2.8.1.

2

What does an attacker need to exploit it?

An attacker must be remotely authenticated and must be able to cause malicious JavaScript to be included in an RSS feed title consumed by the RSS Widget. The payload executes when another authenticated user views the dashboard.

3

Are unauthenticated users affected simply by visiting the dashboard?

No. The described attack requires an authenticated attacker and execution occurs in the browser of an authenticated user viewing the dashboard.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203