CVE-2026-78902: Crafted DNS Reply Enables XSS-to-RCE on pfSense
A flaw in pfBlockerNG on pfSense lets a crafted DNS reply trigger stored XSS when an administrator views Reports, potentially leading to root access. Netgate fixed the issue in pfBlockerNG 3.2.16_1.