Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    CVE-2026-58085 patch?

    Scheduled Pinned Locked Moved General pfSense Questions
    18 Posts 7 Posters 841 Views 11 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W Offline
      wohali
      last edited by

      Hello there,

      CVE-2026-58085 is a serious security vulnerability in the FreeBSD WireGuard implementation that affects FreeBSD 14.4, 15.0, and 15.1.

      By my read that probably affects pfSense Plus 23.x or 24.x thru 26.x, and CE 2.7.x thru 2.9.x.

      When should we expect a pfSense patch to be released for this CVE?

      S 1 Reply Last reply Reply Quote 0
      • S Offline
        slu @wohali
        last edited by

        @wohali did you open a ticket for that in Redmine?

        https://redmine.pfsense.org/projects/pfsense/issues

        pfSense Gold subscription

        1 Reply Last reply Reply Quote 0
        • stephenw10S Offline
          stephenw10 Netgate Administrator
          last edited by

          It will be fixed in 26.07. They should be a new public beta build including the fix shortly.

          S 1 Reply Last reply Reply Quote 0
          • S Offline
            slu @stephenw10
            last edited by

            @stephenw10 is this update also available on 26.03.1 and 2.8.1 with "pkg upgrade"?

            pfSense Gold subscription

            1 Reply Last reply Reply Quote 0
            • stephenw10S Offline
              stephenw10 Netgate Administrator
              last edited by

              No, the fixes for this are in base not a pkg. At least right now.

              S 1 Reply Last reply Reply Quote 0
              • S Offline
                slu @stephenw10
                last edited by

                Mhm, that’s not what I wanted to hear :)
                What do we do with the "old" CE / pfSense+ versions?

                pfSense Gold subscription

                1 Reply Last reply Reply Quote 0
                • stephenw10S Offline
                  stephenw10 Netgate Administrator
                  last edited by

                  Mmm, indeed. It would be far easier to push a new pkg.

                  We are discussing the best solution. Update soon....

                  S 1 Reply Last reply Reply Quote 1
                  • KOMK Offline
                    KOM
                    last edited by KOM

                    If this affects you then you can lower your attack surface by using WAN rules to restrict access to your wg endpoint to known clients only. Obviously that won't work for road warriors coming from random IP addresses. This will not protect you if the wg client has a known IP address on an untrusted network.

                    Also, from what I've read this bug is quite difficult to pull off. An attacker would have to be on the transit path between you and pfsense, and would have to get your receiver index & replay window and then modify your packets in transit in realtime.

                    S 1 Reply Last reply Reply Quote 3
                    • S Offline
                      slu @KOM
                      last edited by

                      @KOM said in CVE-2026-58085 patch?:

                      Obviously that won't work for road warriors coming from random IP addresses.

                      That's my issue :)

                      @KOM said in CVE-2026-58085 patch?:

                      Also, from what I've read this bug is quite difficult to pull off.

                      Yes, I agree with you.

                      pfSense Gold subscription

                      1 Reply Last reply Reply Quote 0
                      • TommyMooT Offline
                        TommyMoo
                        last edited by

                        Hello, just a question, I use a swedish VPN Provider (WireGuard) to which my pfsense, connects to. Does this CVE affect my connection to my VPN Provider to whos server I connect to, via Wireguard?

                        Thank you everyone, I hope anyways, that a patch will be released soon...if this is such a dangerous CVE

                        1 Reply Last reply Reply Quote 0
                        • stephenw10S Offline
                          stephenw10 Netgate Administrator
                          last edited by

                          As a client device you don't open anything on WAN to allow traffic. The firewall connects out to the VPN provider and the open state allows replies only from that IP and port. So only the VPN providers server could attempt to exploit this and your already sending and accepting traffic from them anyway.
                          So, no, there's no risk as a client.

                          TommyMooT 1 Reply Last reply Reply Quote 1
                          • TommyMooT Offline
                            TommyMoo @stephenw10
                            last edited by

                            @stephenw10 Thank you, for explaining, glad its not an issue in my case of use... 😇

                            1 Reply Last reply Reply Quote 0
                            • K Offline
                              khris2fer
                              last edited by

                              What I do is host my own Wireguard vpn server. Just port forward to it thorough NAT. Never was crazy about PFsense version of WG. The OpenVPN VPN is pretty solid I do use that.

                              S 1 Reply Last reply Reply Quote 0
                              • S Offline
                                slu @khris2fer
                                last edited by

                                @khris2fer said in CVE-2026-58085 patch?:

                                The OpenVPN VPN is pretty solid I do use that.

                                For me no option with always on VPN on the smartphone...

                                pfSense Gold subscription

                                1 Reply Last reply Reply Quote 0
                                • S Offline
                                  slu @stephenw10
                                  last edited by

                                  @stephenw10
                                  since there are upcoming versions for CE and pfSense+ that's maybe the best solution?

                                  pfSense Gold subscription

                                  1 Reply Last reply Reply Quote 0
                                  • stephenw10S Offline
                                    stephenw10 Netgate Administrator
                                    last edited by

                                    Yup, patched versions imminent.

                                    GPz1100G 1 Reply Last reply Reply Quote 1
                                    • GPz1100G Offline
                                      GPz1100 @stephenw10
                                      last edited by

                                      @stephenw10 Did this ever drop?

                                      1 Reply Last reply Reply Quote 0
                                      • stephenw10S Offline
                                        stephenw10 Netgate Administrator
                                        last edited by

                                        It's patched in the current 26.07-RC and 2.9.0-Beta versions. It will be in those releases.

                                        1 Reply Last reply Reply Quote 4
                                        • First post
                                          Last post
                                        Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
                                        Privacy Policy · Cookie Policy