CVE-2026-58085 patch?
-
Hello there,
CVE-2026-58085 is a serious security vulnerability in the FreeBSD WireGuard implementation that affects FreeBSD 14.4, 15.0, and 15.1.
By my read that probably affects pfSense Plus 23.x or 24.x thru 26.x, and CE 2.7.x thru 2.9.x.
When should we expect a pfSense patch to be released for this CVE?
-
@wohali did you open a ticket for that in Redmine?
-
It will be fixed in 26.07. They should be a new public beta build including the fix shortly.
-
@stephenw10 is this update also available on 26.03.1 and 2.8.1 with "pkg upgrade"?
-
No, the fixes for this are in base not a pkg. At least right now.
-
Mhm, that’s not what I wanted to hear :)
What do we do with the "old" CE / pfSense+ versions? -
Mmm, indeed. It would be far easier to push a new pkg.
We are discussing the best solution. Update soon....
-
If this affects you then you can lower your attack surface by using WAN rules to restrict access to your wg endpoint to known clients only. Obviously that won't work for road warriors coming from random IP addresses. This will not protect you if the wg client has a known IP address on an untrusted network.
Also, from what I've read this bug is quite difficult to pull off. An attacker would have to be on the transit path between you and pfsense, and would have to get your receiver index & replay window and then modify your packets in transit in realtime.
-
@KOM said in CVE-2026-58085 patch?:
Obviously that won't work for road warriors coming from random IP addresses.
That's my issue :)
@KOM said in CVE-2026-58085 patch?:
Also, from what I've read this bug is quite difficult to pull off.
Yes, I agree with you.
-
Hello, just a question, I use a swedish VPN Provider (WireGuard) to which my pfsense, connects to. Does this CVE affect my connection to my VPN Provider to whos server I connect to, via Wireguard?
Thank you everyone, I hope anyways, that a patch will be released soon...if this is such a dangerous CVE
-
As a client device you don't open anything on WAN to allow traffic. The firewall connects out to the VPN provider and the open state allows replies only from that IP and port. So only the VPN providers server could attempt to exploit this and your already sending and accepting traffic from them anyway.
So, no, there's no risk as a client. -
@stephenw10 Thank you, for explaining, glad its not an issue in my case of use...

-
What I do is host my own Wireguard vpn server. Just port forward to it thorough NAT. Never was crazy about PFsense version of WG. The OpenVPN VPN is pretty solid I do use that.
-
@khris2fer said in CVE-2026-58085 patch?:
The OpenVPN VPN is pretty solid I do use that.
For me no option with always on VPN on the smartphone...
-
@stephenw10
since there are upcoming versions for CE and pfSense+ that's maybe the best solution? -
Yup, patched versions imminent.
-
@stephenw10 Did this ever drop?
-
It's patched in the current 26.07-RC and 2.9.0-Beta versions. It will be in those releases.
Privacy Policy · Cookie Policy