# Netgate pfSense patches multiple RCE flaws

Published: 2026-08-14 · Severity: routine · Sectors: infrastructure
Canonical: https://vorant.io/reports/36738465-bea3-5950-a05c-5d75bf1a685c/netgate-pfsense-patches-multiple-rce-flaws

> ANSSI/CERT-FR flags multiple pfSense CE and Plus vulnerabilities allowing remote code execution, data compromise, and XSS.

CERT-FR issued an advisory covering several vulnerabilities in Netgate's pfSense CE (prior to 2.9.0) and pfSense Plus (prior to 26.07) firewall products. The flaws collectively enable remote attackers to execute arbitrary code, compromise data confidentiality and integrity, and perform indirect remote code injection via cross-site scripting (XSS). Netgate published a series of security bulletins (pfSense-SA-26_06 through SA-26_21) on 13 August 2026 detailing the individual issues, with four CVEs assigned: CVE-2026-56126, CVE-2026-56127, CVE-2026-56128, and CVE-2026-67189.

No exploitation in the wild is reported; this is a vendor-driven patch disclosure. Given pfSense's widespread use as a perimeter firewall/router in SMB, enterprise, and home-lab environments, unpatched instances present a notable attack surface, particularly given the RCE potential. Administrators should apply the referenced patches per Netgate's bulletins promptly, as no workaround details are provided in the advisory.

## Mentioned in this report

- Vulnerabilities: CVE-2026-56126, CVE-2026-56127, CVE-2026-56128, CVE-2026-67189

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1022

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/36738465-bea3-5950-a05c-5d75bf1a685c/netgate-pfsense-patches-multiple-rce-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
