
The FreeBSD project released a number of security advisories yesterday. We're still reviewing them. So far, one does not impact MidnightBSD (setcred), and two more do: CVE-2026-39461 (libcasper) and CVE-2026-45254. We've patched the latter in git on master and stable/4.0
Post summary
The FreeBSD project announced several advisories, identified two affecting MidnightBSD (one involving libcasper), and confirmed that a patch has been applied to the affected repository branches.
