CVE-2026-78902: Netgate pfSense vulnerability
Published Sep 25, 2026
·Updated
Cross Site Scripting vulnerability in Netgate pfSense 26.03.1-RELEASE allows an attacker to execute arbitrary code via the pfBlockerNG package
Affected Software
1 affected component
Netgate pfSense=26.03.1-RELEASE
Event History
Sep 25, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Which systems should be prioritized for review?
Prioritize Netgate pfSense 26.03.1-RELEASE systems that have the pfBlockerNG package installed, as the issue is identified as being reachable through that package.