[NEW] [high] FreeBSD Project FreeBSD OS: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in FreeBSD Project FreeBSD OS to escalate privileges and potentially gain root rights, bypass security measures, execute arbitrary code, manipulate or disclose data, or cause denial-of-service conditions.
CSIRTS triage
- What
- Multiple vulnerabilities allow privilege escalation to root, code execution, denial of service, data manipulation, and security bypass.
- Who is affected
- FreeBSD OS installations; specific affected versions not detailed in advisory.
- Urgency
- High severity with multiple exploitation vectors; prioritize patching to prevent privilege escalation.
- Action
- Apply FreeBSD security updates addressing CVE-2026-14457, CVE-2026-18798, CVE-2026-54874, and CVE-2026-58089 through CVE-2026-58093.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch FreeBSD OS
Get an email when a new FreeBSD OS advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3034
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-144570.98% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 60% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-187981.5% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 72% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-548740.52% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 42% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-580890.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-580900.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-580910.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-580920.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-580930.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-580940.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-580950.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-14457 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-18798 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-54874 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58089 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58090 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58091 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58092 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58093 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58094 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58095 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58096 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58097 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-63072 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-63073 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-63074 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-63075 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-63076 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] OpenSSL: Multiple vulnerabilitiescert-bund
- highCVE-2026-58097: mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing …nvd
- criticalCVE-2026-58096: LcpDecodeConfig() did not validate the length of received endpoint discriminator options again…nvd
- criticalCVE-2026-58095: mp_Enddisc() used incorrect length calculations when formatting endpoint discriminator address…nvd
- highCVE-2026-58094: The FIOSSHMLPGCNF ioctl(2) operation configures the page size for a largepage shared memory ob…nvd
- highCVE-2026-58093: The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the process tree lock. Afte…nvd
- mediumCVE-2026-58092: In FreeBSD 15.0, the kernel structure used to represent user credentials changed: previously t…nvd
- highCVE-2026-58091: The implementation of this ioctl attempts to acquire locks on all channels in a sync group. If…nvd
- highCVE-2026-58090: The SOCK_STREAM receive path in the unix socket implementation failed to fully detach control …nvd
- highCVE-2026-58089: When a process calls execve(2) to execute a setuid or setgid image, hwpmc(4) is supposed to de…nvd
- unknownMultiple vulnerabilities in OpenSSL (August 26, 2026)cert-fr-avis
- unknownUSN-8678-2: OpenSSL, OpenSSL 1.0 vulnerabilitiesubuntu
Recent advisories for FreeBSD Project FreeBSD OS
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] FreeBSD Project FreeBSD OS: Multiple vulnerabilitiescert-bund · 2026-08-20
- medium[NEW] [medium] FreeBSD Project FreeBSD OS: Multiple vulnerabilitiescert-bund · 2026-08-20
- high[UPDATE] [high] FreeBSD Project FreeBSD OS: Multiple Vulnerabilitiescert-bund · 2026-08-13
More from CERT-Bund (BSI) Security Advisories
- low[NEW] [low] Insyde UEFI Firmware: Vulnerability allows unspecified attack2026-08-26
- medium[NEW] [medium] OPNsense: Vulnerability allows bypass of security measures2026-08-26
- medium[NEW] [medium] SQLite: Vulnerability allows denial of service2026-08-26
- high[NEW] [high] DNN: Multiple vulnerabilities2026-08-26
- high[NEW] [high] GitLab: Multiple vulnerabilities2026-08-26