pfSense Plus RELEASE 26.03.1

pfSense Plus RELEASE 26.03.1

pfSenseⓇ plus software, Release 26.03.1, is available now!

pfSense Plus Software Release

Release Details

This is a software maintenance release focused on security fixes, stability improvements, and targeted usability enhancements for pfSense Plus 26.03:

  • Security and WebGUI hardening: Addresses multiple potential XSS vulnerabilities across the WebGUI, including diag_arp.php when using ISC DHCP, RSS Widget feed content post titles, and the Captive Portal widget. These fixes strengthen administrative interface security and reduce exposure to stored or reflected script injection risks.
  • FreeBSD and base system security updates: Includes several security and errata fixes merged from FreeBSD, including DHCP client vulnerability fixes, along with updated base system packages to address upstream security issues.
  • Authentication and user management fixes: Corrects LDAP shell authentication so configured group DN restrictions are properly enforced, and fixes an issue where creating a new user could ignore the certificate checkbox value when certificate fields were populated.
  • Captive Portal reliability improvements: Restores logging of Captive Portal authentication messages and includes security fixes for the Captive Portal dashboard widget, improving both visibility and safety for environments using portal-based access control.
  • Firewall, NAT, and alias enhancements: Improves alias list visibility by increasing the amount of system alias content displayed. Adds MAP-E port set (PSID) support to manual outbound NAT rules and fixes duplication behavior for floating rules using the “This Firewall (self)” source option.
  • VPN stability and usability fixes: Fixes an IPsec daemon crash that could occur if a peer initiated two rekeys for the same child SA. OpenVPN behavior is also improved by restoring missing OpenVPN networks in the automatically generated vpn_networks table and preventing all OpenVPN instances from restarting when applying changes to a single assigned interface.
  • System stability improvements: Resolves a kernel panic caused by a race condition on a bpf device, improving overall platform reliability under affected network capture or filtering conditions.
  • Dynamic DNS, PHP, console, and Wake on LAN fixes: Adds improved RFC2136 Dynamic DNS error logging, fixes PHP errors caused by NULL bytes in IP addresses, prevents repeated Ctrl-C actions from entering the password change flow in the console menu, and improves consistency when sending Wake on LAN packets.

 

These updates reinforce pfSense Plus 26.03.1 as a security-focused maintenance release, improving platform stability, VPN reliability, firewall rule handling, and administrative interface protection.

Learn more by viewing the Release Notes.

Users running pfSense Plus on Netgate Appliances

Netgate-branded appliances come with TAC Lite support and receive this and future software updates at no additional cost for the lifetime of the unit.

Upgrading from an earlier version of pfSense Plus software is typically conducted via the user interface. To ensure data integrity and recovery options, it’s crucial to back up your pfSense Plus configuration before initiating any significant changes, including upgrades. Detailed Backup and Recovery guidelines are available in the pfSense documentation available here: Backup and Recovery.

Instruction to upgrades from the user interface:

  • Navigate to System > Update
  • Set Branch to “Current Stable Version (26.03.1)
  • Click Confirm to start the upgrade process

Users running pfSense Plus on their own hardware

Upgrading pfSense on your own hardware follows the same procedure as on Netgate appliances, provided you have a valid subscription. If you need to renew your pfSense Pluse Software Subscription, please visit our online shop.

Users running pfSense Community Edition (CE)

We recommend upgrading from pfSense CE to pfSense Plus to take full advantage of the enhanced features and benefits of the Plus version. You can easily upgrade your pfSense CE by purchasing an activation token (pfSense+ Software Subscription).

If you need assistance to migrate from pfSense CE to pfSense Plus, talk with our certified pfSense Engineers.

ITG Customers

If you are an ITG customer with an active maintenance package or support contract, your are all covered. We will reach out to you shortly to finalize the details of the upgrade, which we will handle on your behalf.

Get in touch to receive support or a maintenance package from ITG