core
opnsense- Software type
- —
- Catalog vulnerabilities
- 7
Severity across 7 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 7 analyzed records
A short verification protects source data and prevents automated AI requests.
The GCVE catalog currently lists 7 vulnerability records affecting core.
Among the 7 records analyzed by CyStack, 5 are High or Critical and 0 appear in the CISA KEV catalog.
Compare the version you run with each vulnerability and the provider guidance below. The data only includes records analyzed so far.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan
| CVE | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-53581ntp: write path traversal | Exploitation statusPublic exploit | FixNot confirmed | Published09/08/2026 | SeverityCritical |
CVE-2026-45158OPNsense: Command Injection via Attacker-Controlled DHCP Config | Exploitation statusNot known exploited | FixYes | Published05/13/2026 | SeverityCritical |
CVE-2026-44194OPNsense: RCE on user managment | Exploitation statusPublic exploit | FixYes | Published05/13/2026 | SeverityCritical |
CVE-2026-44195OPNsense: Authentication lockout bypass | Exploitation statusPublic exploit | FixYes | Published05/13/2026 | SeverityMedium |
CVE-2026-44193OPNsense: RCE via XMLRPC endpoint using `opnsense.restore_config_section` method | Exploitation statusPublic exploit | FixYes | Published05/13/2026 | SeverityCritical |
CVE-2026-34578OPNsense has an LDAP Injection via Unsanitized Username in Authentication | Exploitation statusPublic exploit | FixYes | Published04/09/2026 | SeverityHigh |
CVE-2026-30868Cross-Site Request Forgery (CSRF) in opnsense/core | Exploitation statusPublic exploit | FixYes | Published03/11/2026 | SeverityMedium |