CVE-2026-78902

LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

0.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 3 mentions (2026-09-22); latest day: 2
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-09-22: 3Mentions · 2026-09-23: 209-2209-23
Referenced assets3 URLs
Full discourse5 posts
  • DFIR Radar@DFIR_Radar

    CVE-2026-78902 turns a single DNS request into root on pfSense. An attacker on the LAN poisons the pfBlockerNG reply log via crafted DNS TXT RDATA, triggering stored XSS that chains to full RCE when an admin loads the Stats tab. - CVE-2026-78902 affects pfBlockerNG on pfSense when Unbound Python mode and DNS Reply Logging are both enabled. The flaw originates in pfb_unbound.py: convert_other() passes printable ASCII chars including <, >, ", and = through without sanitization, and the resulting r_addr value is written raw into /var/log/pfblockerng/dns_reply.log and unified.log. - pfblockerng_alerts.php renders $fields[8] (the resolved address) directly into HTML with no htmlspecialchars() call, both in visible cell content and a title attribute. The Stats tab is the dangerous sink: it reads the full log file, de-duplicates with uniq -c, and renders aggregated values into table cells, filter-button attributes, and pie chart labels, all unescaped, persisting for the lifetime of the log entry. - The full chain: attacker controls a DNS server returning a crafted TXT record, forces any LAN client to resolve it through pfSense, payload is logged, admin views Stats tab, XSS fires, fetches /diag_command.php, scrapes a CSRF token, POSTs a shell command, and a reverse root shell connects back. - Netgate patched within 24 hours (v. #DFIR_Radar

    11010151
    1.9K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews

    NetSPI disclosed a pfBlockerNG flaw in pfSense where a crafted DNS reply could poison logs, trigger stored XSS in webConfigurator, and chain to root RCE. Fixed quickly, later assigned CVE. #pfSense #pfBlockerNG #Netgate https://www.hendryadrian.com/cve-2026-78902-xss-to-rce-in-pfsense-with-one-dns-request/

    00000222
    4.8K followersView on X
  • Anthony Bahn@HoustonIntrove1

    pfBlockerNG DNS Reply logging just became a root path. One crafted TXT reply, admin views the Stats tab, you're owned via /diag_command.php. CVE-2026-78902. Get to 3.2.16_1 tonight if that package is installed.

    0000029
    30 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc

    TRC analysis shows attackers can exploit CVE-2024-46538 to compromise pfSense firewalls with a single malicious DNS request. The attack chains stored XSS through pfBlockerNG logs to achieve root access on network edge devices. Compromising perimeter infrastructure provides privileged positions for lateral movement into internal network segments. #ZeroTrust #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/cve-2026-78902-xss-rce-pfsense-dns-request

    0000038
    2.0K followersView on X
  • DFIR Radar@DFIR_Radar

    Source: https://www.netspi.com/blog/technical-blog/web-application-pentesting/cve-2026-78902-xss-to-rce-in-pfsense-with-one-dns-request/

    0000055
    1.9K followersView on X

Explore more