pfSense Plus RELEASE 26.07

pfSense Plus RELEASE 26.07

pfSenseⓇ plus software, Release 26.07, is available now!

pfSense Plus Software Release

Release Details

This is a feature-focused pfSense Plus release introducing new Nexus-exclusive networking and security capabilities, alongside critical security updates, platform fixes, and a major step toward Netgate’s next-generation management experience for pfSense Plus 26.07:

  • CoreDNS and high-performance DNS services: Introduces CoreDNS as a new integrated DNS component available through the Netgate Nexus controller. Powered by Netgate’s exclusive rexdns plugin, CoreDNS is designed to process DNS-based tasks efficiently while providing a foundation for more advanced DNS management capabilities.
  • Threatgate address and domain list management: Adds Threatgate, a high-performance component for managing large collections of IP addresses and domains used by firewall rules, aliases, and CoreDNS groups. Administrators can block these lists directly or build customized policies around their contents.
  • Integrated CoreDNS and Threatgate processing: CoreDNS and Threatgate are designed to work closely together, allowing pfSense Plus systems to rapidly process and apply very large address and domain lists while maintaining strong performance, including on smaller and resource-constrained appliances.
  • Snort 3 intrusion prevention support: Introduces Snort version 3 through the Netgate Nexus controller GUI. The updated IPS platform adds multi-threading support and a faster rule syntax, providing improved performance and a more modern foundation for network intrusion detection and prevention. If you’re running IPS/IDS on pfSense, now’s a good time to review your signature coverage. We supply Snort Business signature subscriptions for pfSense, giving you access to a maintained, high-quality ruleset rather than relying on community feeds alone: šŸ‘‰ https://itg-shop.co.uk/snort-for-pfsense.html
  • WireGuard and security updates: Includes a critical security update addressing the WireGuard vulnerability CVE-2026-58085, along with additional security enhancements intended to strengthen the overall security posture of pfSense Plus deployments.
  • Networking and service reliability improvements: Includes fixes and enhancements across DHCP, DNS Resolver, Dynamic DNS, gateway monitoring, IPsec, VXLAN interfaces, OpenVPN, firewall rules and NAT, traffic shaping, and wireless support.
  • New Netgate Nexus management experience: Expands access to Netgate’s completely rewritten management architecture built on Go, replacing the limitations of the legacy PHP-based interface with a faster, more responsive platform featuring a full-featured API and improved cross-platform capabilities.
  • Simplified Nexus activation: Administrators can enable the new interface from System > Advanced > Netgate Nexus, then access the Nexus controller on port 8443 of the firewall. The same interface is designed to support both individual pfSense Plus appliances and larger firewall fleets.

Platform compatibility considerations: Some virtual machines and third-party platforms may not support the new Nexus GUI where the machine information required by the software is unavailable.

Learn more by viewing the šŸ‘‰ Release Notes.

Users running pfSense Plus on Netgate Appliances

Netgate-branded appliances come with TAC Lite support and receive this and future software updates at no additional cost for the lifetime of the unit.

Upgrading from an earlier version of pfSense Plus software is typically conducted via the user interface. To ensure data integrity and recovery options, it’s crucial to back up your pfSense Plus configuration before initiating any significant changes, including upgrades. Detailed Backup and Recovery guidelines are available in the pfSense documentation available here: Backup and Recovery.

Instruction to upgrades from the user interface:

  • Navigate to System > Update
  • Set Branch to ā€œCurrent Stable Version (26.07)ā€
  • Click Confirm to start the upgrade process

Users running pfSense Plus on their own hardware

Upgrading pfSense on your own hardware follows the same procedure as on Netgate appliances, provided you have a valid subscription. If you need to renew your pfSense Pluse Software Subscription, please visit our online shop.

Users running pfSense Community Edition (CE)

We recommend upgrading from pfSense CE to pfSense Plus to take full advantage of the enhanced features and benefits of the Plus version. You can easily upgrade your pfSense CE by purchasing an activation token (pfSense+ Software Subscription).

If you need assistance to migrate from pfSense CE to pfSense Plus, talk with our certified pfSense Engineers.

or

ITG Customers

If you are an ITG customer with an active maintenance package or support contract, your are all covered. We will reach out to you shortly to finalize the details of the upgrade, which we will handle on your behalf.

Should we upgrade now, or wait?

Releases like this raise the same question for every firewall owner: should we upgrade now, or wait?
The honest answer is: it depends on your environment. Which features you use, which you don’t, whether you’re exposed by the CVE, and how much early/new code you’re willing to carry before the first point release, these all change the calculation. We recently walked a client through exactly this, confirming they weren’t affected by the WireGuard vulnerability and recommending a short hold given how much new code shipped, rather than a reflexive “upgrade everything now.” This is exactly what our pfSense/Netgate maintenance packages cover:

  • Impact assessment for every release against your specific configuration
  • Clear upgrade / hold recommendations, not blanket advice
  • Scheduled upgrades with full backup and rollback planning
  • Ongoing monitoring so nothing critical slips past you
Get in touch to receive support or a maintenance package from ITG