Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

CVE-2026-78902: XSS to RCE in pfSense with one DNS request

Summary

NetSPI reports CVE-2026-78902, a stored cross-site scripting issue in the pfSense pfBlockerNG package that can be escalated to remote code execution with a single DNS request.
CVE
CVE-2026-78902
Published
Collected

original ↗