
🚨 NEW PFSENSE VULNERABILITY CAN LEAD TO ARBITRARY PHP CODE EXECUTION A new vulnerability was published today affecting Netgate pfSense. Tracked as: CVE-2026-97730 CVSS: 8.5 HIGH Affected versions include: pfSense Plus before 26.07 and pfSense CE before 2.9.0. The vulnerability involves local-file inclusion in the pfSense dashboard widget-sequence handling. Under the required conditions, an authenticated attacker able to modify dashboard settings and place a file on the firewall can use path traversal to cause pfSense to load an arbitrary PHP file as a dashboard widget. That can result in arbitrary PHP-code execution. Important limitation: This is not an unauthenticated internet RCE. The attacker needs specific authenticated privileges and the ability to place a file on the system. But pfSense often occupies an extremely privileged position in enterprise networks. Compromise of a firewall-management plane can expose: network configuration VPN infrastructure routing credentials security policies internal network visibility. 🛡️ Upgrade to the vendor-fixed release where applicable. Sources: CVE record · Netgate references · Vulners.


