Opnsense is a modestly represented open-source firewall and routing platform that punches above its volume in the vulnerability landscape, deployed across enterprise networks and critical infrastructure segments where network security appliances serve as chokepoints. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and a moderate tendency toward public exploit availability; the software's administrative web interface and command-execution pathways have repeatedly surfaced exploitable weaknesses. The exposure recurs through input-validation and access-control weakness classes including cross-site scripting, command injection, argument injection, permission misconfiguration, and cross-site request forgery, reflecting the complexity of building a secure web-administered system that bridges user input to privileged network operations. Defenders should prioritize patch deployment for this vendor given its role as a security boundary and the severity profile of its disclosures; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opnsense over time
Signals from CVEs in this vendor scope (37 CVEs).
37 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-1000479HIGH pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrary code, because the error detection occu | Jan 3, 2018 | 8.8 | 55 | NO | YES |
CVE-2026-44194CRITICAL OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, an authenticated Remote Code Execution (RCE) vulnerability in the OPNsense core allows a user with user- | May 13, 2026 | 9.1 | 39 | NO | NO |
CVE-2026-45158CRITICAL OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, unsanitized user input is passed to the DHCP configuration of the configured interface, which is process | May 13, 2026 | 9.1 | 36 | NO | NO |
CVE-2023-39007CRITICAL /ui/cron/item/open in the Cron component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows XSS via openAction in app/controllers/OPNsense/Cron/Ite | Aug 9, 2023 | 9.6 | 36 | NO | YES |
CVE-2026-44193CRITICAL OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, the XMLRPC method opnsense.restore_config_section fails to sanitize user supplied input leading to Remot | May 13, 2026 | 9.1 | 35 | NO | NO |
CVE-2025-50989CRITICAL OPNsense before 25.1.8 contains an authenticated command injection vulnerability in its Bridge Interface Edit endpoint (interfaces_bridge_edit.php). The span POST parameter is conc | Aug 27, 2025 | 9.1 | 32 | NO | NO |
CVE-2023-39004CRITICAL Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow attackers to access sensitive inform | Aug 9, 2023 | 9.8 | 32 | NO | NO |
CVE-2023-39008CRITICAL A command injection vulnerability in the component /api/cron/settings/setJob/ of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execu | Aug 9, 2023 | 9.8 | 30 | NO | NO |
CVE-2020-23015MEDIUM An open redirect issue was discovered in OPNsense through 20.1.5. The redirect parameter "url" in login page was not filtered and can redirect user to any website. | May 3, 2021 | 6.1 | 30 | NO | YES |
CVE-2026-34578HIGH OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.6, OPNsense's LDAP authentication connector passes the login username directly into an LDAP search filter w | Apr 9, 2026 | 8.2 | 28 | NO | NO |
Signals from CVEs in this vendor scope (37 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opnsense.
Media articles that mention a CVE ID that affects a product developed by Opnsense — matched by CVE ID, not by vendor name.