SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-78849

MEDIUM · CVSS 5.4 EPSS 0.36%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Netgate pfSense Plus software versions up to 26.03 and pfSense CE versions up to 2.8.1 are vulnerable to a Cross Site Scripting (XSS) flaw that can be exploited by remote attackers through the captive_portal_status.widget.php file, potentially allowing them to execute arbitrary code. Organizations using these versions of pfSense should prioritize remediation to mitigate the risk of unauthorized access and code execution.

CVE
CVE-2026-78849
Severity
MEDIUM
CVSS
5.4
EPSS
0.36%

Original NVD Description

Cross Site Scripting vulnerability in Netgate pfSense Plus software versions <= 26.03 pfSense CE software versions <= 2.8.1 allows a remote attacker to execute arbitrary code via the captive_portal_status.widget.php file