Skip to main content

Share story

Security

OPNsense update fixes critical root vulnerability and other security risks

OPNsense update fixes critical root vulnerability and other security risks Image: Primary
OPNsense released versions 26.1.11 and 26.4.1(p1) to fix a critical root vulnerability and other security risks. The update addresses CVE-2026-57155, a flaw in the GeoIP alias component that could allow privilege escalation to root under certain conditions. According to explanations by vulnerability discoverer Jonas Ampferl, earlier versions did not sufficiently check the address or content of the database file, potentially allowing remote attackers to download manipulated archives and execute code as root. The vulnerability could be exploited with low access rights, including permission to edit firewall aliases. Users are advised to update their installations. Further details on the fixed vulnerabilities, ranging from moderate to high severity, are available in the advisory overview in the OPNsense GitHub repository. Release notes and update guides are provided for both Community and Business Editions.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from heise.de and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
AI Products
AI Products

SoftBank seeks up to $100 billion from Gulf investors for AI

SoftBank Group Corp. is seeking to raise as much as $100 billion from investors in the Gulf region to help finance an expansion of the company's investments in artificial intelligence, the Financial Times has reported....

AI Science
AI Science

Nullify preprint reports selective LLM forgetting without weight updates

Researchers report in a preprint that Nullify, a method designed to suppress specific memorized information in large language models, matches or surpasses established forgetting baselines on TOFU and MUSE while preserving model ut...

AI Science
AI Science

Preprint reports schema-free generation of valid enterprise test data

Researchers report in an arXiv preprint that their Generalist Populator agent generated enterprise data with 100% constraint satisfaction and 0.88 average marginal fidelity across ten simulated environments without accessing datab...

AI Science
AI Science

Preprint reports task-completion gains from agent-generated interfaces

Researchers report in an arXiv preprint that training an agent to generate interactive interfaces improved a 4B model's Pass@3 task-completion score from 9.33% to 58.00%. Their GenUI-Harness pairs an agent that retrieves informati...