PT-2026-85780 · Undefined · Undefined

CVE-2026-38961

·

Published

2026-09-04

·

Updated

2026-09-12

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVE-2026-38961: Stored XSS in Netgate pfSense RSS Widget (versions 26.03, 25.11.1, CE 2.8.1). Malicious feed titles execute JS for any authenticated user viewing the dashboard. CVSS: N/A. Unpatched—restrict RSS access now. Details: https://t.co/XaOt7Xazw4 #cybersecurit #valtersit #CVE #CVEAlert #infosec #SysAdmin #cybersecurity #Linux #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland #estonia #lithuania #ireland #hungary #denmark #norway #malta #mexico #switczerland #china #france #germany #docker #kali

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-38961

Affected Products

Undefined