CVE-2026-78902: XSS to RCE in pfSense with one DNS request
netspi.com | vulnerability | CVE-2026-78902 | #rce | #xss | #vulnerability-analysis | #exploit-chain | #firewall | #pfsense | #cve-2026-78902 | #pfblockerng
Summary
NetSPI reports CVE-2026-78902, a stored cross-site scripting issue in the pfSense pfBlockerNG package that can be escalated to remote code execution with a single DNS request.
- CVE
- CVE-2026-78902
- Published
- Collected
Skip to content