logo

OPNsense Critical Root RCE (CVE-2026-44194 & CVE-2026-45158) Details and PoC Disclosed

ID: 067f01dc-ed17-5e1d-8db9-eef937c55e25

STIX ID: report--067f01dc-ed17-5e1d-8db9-eef937c55e25

Feed Name: securityonline.info

Threat Score
86/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: Ddos

...
...

The report discloses two critical OPNsense vulnerabilities (CVE-2026-44194 and CVE-2026-45158) that allow authenticated users with limited privileges to achieve root remote command execution through shell injection in quoted email local-parts and unsanitized DHCP hostnames; public PoC is available and administrators are urged to update all affected systems (<= 26.1.7) to OPNsense 26.1.8 immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.