Skip to content
VulniPulse

Netgate pfSense Security Advisories & CVEs

8 advisories tracked · Netgate Security Advisories + NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor pfSense CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your pfSense device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in pfSense's recent advisories.

Official source

Netgate Security Advisories + NVD

Netgate maintains a dedicated Security Advisory index for pfSense (docs.netgate.com/advisories), but pfSense CVEs are assigned by MITRE and third-party researchers rather than a Netgate CNA — so VulniPulse ingests them from NVD (keyword-filtered to pfSense, dropped unless a pfSense/Netgate product is named) and links back to the Netgate advisory or pfSense reference. Covers pfSense CE (Community Edition) and pfSense Plus — a firewall/router at the network edge where a bug is directly internet-exposed.

Latest pfSense advisories

Critical9.9pfSense

Critical [CVE-2025-69691] Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php

Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call is only available to admins and they are intentionally allowed to execute PHP code.

CVE-2025-69691
pfSense CE
May 8, 2026
Critical9.1pfSense

Critical [CVE-2025-69690] Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the post_reboot_commands property

Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the post_reboot_commands property. NOTE: the Supplier disputes this because this installer is only available to admins and they are intentionally allowed to execute PHP code.

CVE-2025-69690
pfSense CE
May 8, 2026
Critical9.8pfSense

Critical [CVE-2023-29974] issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements

An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements.

CVE-2023-29974
pfSense CE
Nov 8, 2023
Critical9.6pfSense

Critical [CVE-2020-21487] Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3

Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via the RootFolder field of acme_certificates.php.

CVE-2020-21487
Unclassified
Apr 4, 2023
Critical9.8pfSense

Critical [CVE-2023-27100] Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1…

Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force protection mechanisms via crafted web requests.

CVE-2023-27100
pfSense PluspfSense CE
Mar 22, 2023
Critical9.8pfSense

Critical [CVE-2022-31814] pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root

pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header. NOTE: 3.x is unaffected.

CVE-2022-31814
Unclassified
Sep 5, 2022
Critical9.8pfSense

Critical [CVE-2019-16915] pfSense: issue was discovered in pfSense through 2.4.4-p3.

An issue was discovered in pfSense through 2.4.4-p3. widgets/widgets/picture.widget.php uses the widgetkey parameter directly without sanitization (e.g., a basename call) for a pathname to file_get_contents or file_put_contents.

CVE-2019-16915
Unclassified
Sep 26, 2019
Critical9.8pfSense

Critical [CVE-2019-12585] Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in…

Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_status.php.

CVE-2019-12585
Unclassified
Jun 3, 2019

← All vendors