# Netgate pfSense RCE flaw patched

Published: 2026-09-16 · Severity: routine · Sectors: infrastructure, technology
Canonical: https://vorant.io/reports/7c2c93e7-74be-58c3-a627-ac97804c9cc7/netgate-pfsense-rce-flaw-patched

> CERT-FR advisory warns of a remote code execution vulnerability in Netgate pfSense CE and Plus firewall software.

CERT-FR has published an advisory regarding a vulnerability in Netgate pfSense, a widely used open-source firewall/router platform. The flaw allows an attacker to achieve remote code execution, though the advisory does not detail the attack vector, prerequisites, or whether exploitation has been observed in the wild.

Affected versions are pfSense CE prior to 2.9.0 and pfSense Plus prior to 26.07. Netgate has released a security bulletin (pfSense-SA-26_22) with patches; defenders running pfSense should upgrade to the fixed versions referenced in the vendor bulletin as soon as possible, particularly given pfSense's common deployment as perimeter/edge firewall infrastructure, which makes RCE flaws in it high-value targets for network compromise.

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1181

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/7c2c93e7-74be-58c3-a627-ac97804c9cc7/netgate-pfsense-rce-flaw-patched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
