Netgate Releases pfSense Community Edition Version 2.9.0
Products
pfSense Plus Software
Overview
Features
Performance
Technology
Cloud
Resources
pfSense Plus vs TNSR
FAQ
TNSR Software
Overview
Features
Performance
Technology
Cloud
Resources
pfSense Plus vs TNSR
FAQ
Netgate NexusNew
Overview
FAQ
Buy a Nexus License
Appliances
Overview
pfSense Plus Appliances
TNSR Appliances
TAA Compliance
Comparison Table
Buy a pfSense+ Appliance Buy a TNSR Appliance
Applications
pfSense Plus Applications
Firewall
Router
VPN
Attack Prevention
TNSR Applications
High-Performance Edge Routing
High-Throughput Site-to-Site IPsec
IPv4 Address Space Exhaustion
High-Speed Cloud Connectivity
Customers
By Solution
Firewall
Router
VPN
Attack Prevention
High-Performance Edge Routing
High-Throughout Site-to-Site IPsec
By Industry
Aerospace & Defense
Construction
Defense
Education
Healthcare
IT Services
Featured Story
USNS Mercy
U.S. Navy deploys pfSense Plus software on the Netgate 1537 and AWS Cloud for network security and management.
Read Full Story
Pricing
pfSense+ Software
Overview
Appliances
Cloud
TNSR Software
Overview
Appliances
Cloud
Services
Consulting
Implementation
Training
Support
Support
Support Subscriptions
Overview
TAC Lite
TAC Pro
TAC Enterprise
Business Assurance
Contact Support
Resources Library
Overview
Articles
Data Sheets
Newsletters
Solution Briefs
Technical Papers
Whitepapers
Videos
Documentation
Product Lifecycle
Security
Services
Professional Services
Training
pfSense Fundamentals and Advanced Application
Company
Latest
Blog
Press
Newsletter
Events
Partner
Partner Locator
Partner Program
Partner Application
Partner Login
Company
About Us
Careers
Contact Us
Buy Now
Back to Blog
pfSense,
Releases
Netgate Releases pfSense Community Edition Version 2.9.0
Written by: Netgate
Date: August 20, 2026
pfSense® software, the world’s leading firewall, router, and VPN solution, provides secure network edge and cloud networking solutions for millions of deployments worldwide.
Netgate® is excited to announce the release of pfSense Community Edition (CE) software version 2.9.0. This new version includes over 150 new features, enhancements, and fixes. All pfSense CE users are encouraged to upgrade to this new version.
Feature Highlights
This release software includes a large number of security and feature enhancements. Some highlights include:
SSH Algorithms
This release includes several changes to algorithms for the SSH daemon for key exchange, encryption, and message authentication. These changes increase security by including post-quantum key exchange algorithms and by removing older and weaker algorithms.
TLS Certificate Strength
The version of OpenSSL in this release further tightens certificate requirements and removes support for certain weak properties. For example, if a TLS server certificate for a service such as the GUI has a weak key (
TLS Certificate Auto-Renew
This version of pfSense software can automatically renew TLS server certificates which are self-signed or signed by an internal CA stored in the pfSense software configuration. Automatic renewal is a per-certificate option, and pfSense software automatically enables this option for the GUI certificate when possible. When automatically renewing a certificate, pfSense software uses the latest strict security options to ensure the certificate meets current standards.
Endpoint-independent Port Restricted Cone Outbound NAT
This version includes partial experimental support for “Port Restricted Cone” endpoint-independent outbound NAT. “Port Restricted Cone” NAT mappings attempt to preserve port and external address mappings for clients when speaking to multiple remote hosts, but in a dynamic way that does not rely on static port NAT. This helps avoid issues with multiple local clients using the same source port to the same remote host.
Security Updates
This Release software includes critical security updates for WireGuard (CVE-2026-58085), as well as fixes for the following security fixes:
pfSense-SA-25_09.sshguard: Anti-brute force protection bypass and potential denial of service
pfSense-SA-26_01.webgui: The isvalidpid() function does not properly check or escape PID file parameter
pfSense-SA-26_02.webgui: Potential XSS in Delegated Length value for Prefix Delegation on services_dhcpv6.php when using Kea
pfSense-SA-26_03.webgui: Potential Stored XSS in diag_arp.php when using ISC DHCP
pfSense-SA-26_04.webgui: Potential XSS in RSS Widget feed content post titles
pfSense-SA-26_05.webgui: Potential XSS in Captive Portal widget
Security and errata fixes were merged from FreeBSD, including fixes for vulnerabilities discovered in OpenSSL and the DHCP client, and base system packages were updated to address various upstream security issues.
Operating System and Base Component Updates
Numerous systems were updated,...