Firewalld is a host-based firewall management utility that dynamically configures iptables rules and network policies in Linux environments, occupying a focused position in the system administration and network security toolchain. Its disclosures center on authentication and permission-handling issues within the firewall control interface itself, reflecting the access-control and privilege-boundary demands of a privileged management daemon. Current CVE counts, severity distributions, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Firewalld over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-4948MEDIUM A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicySe | Mar 27, 2026 | 5.5 | 22 | NO | NO |
CVE-2016-5410MEDIUM firewalld.py in firewalld before 0.4.3.3 allows local users to bypass authentication and modify firewall configurations via the (1) addPassthrough, (2) removePassthrough, (3) addEn | Apr 19, 2017 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Firewalld.
Media articles that mention a CVE ID that affects a product developed by Firewalld — matched by CVE ID, not by vendor name.