pfSense® software, the world’s leading firewall, router, and VPN solution, provides secure network edge and cloud networking solutions for millions of deployments worldwide. Netgate® is excited to announce the release of pfSense Community Edition (CE) software version 2.9.0. This new version includes over 150 new features, enhancements, and fixes. All pfSense CE users are encouraged to upgrade to this new version. This release software includes a large number of security and feature enhancements. Some highlights include: This release includes several changes to algorithms for the SSH daemon for key exchange, encryption, and message authentication. These changes increase security by including post-quantum key exchange algorithms and by removing older and weaker algorithms. The version of OpenSSL in this release further tightens certificate requirements and removes support for certain weak properties. For example, if a TLS server certificate for a service such as the GUI has a weak key (<2048 bits), the service may fail with an error such as “key too small”. This version of pfSense software checks the GUI certificate during the upgrade process and will re-generate a new GUI certificate if the current certificate is invalid, expired, or weak. This version of pfSense software can automatically renew TLS server certificates which are self-signed or signed by an internal CA stored in the pfSense software configuration. Automatic renewal is a per-certificate option, and pfSense software automatically enables this option for the GUI certificate when possible. When automatically renewing a certificate, pfSense software uses the latest strict security options to ensure the certificate meets current standards. This version includes partial experimental support for “Port Restricted Cone” endpoint-independent outbound NAT. “Port Restricted Cone” NAT mappings attempt to preserve port and external address mappings for clients when speaking to multiple remote hosts, but in a dynamic way that does not rely on static port NAT. This helps avoid issues with multiple local clients using the same source port to the same remote host. This Release software includes critical security updates for WireGuard (CVE-2026-58085), as well as fixes for the following security fixes: Security and errata fixes were merged from FreeBSD, including fixes for vulnerabilities discovered in OpenSSL and the DHCP client, and base system packages were updated to address various upstream security issues. Numerous systems were updated, including: Certain hardware with a specific firmware problem, including some Celeron J devices, may encounter a kernel panic when attempting to boot pfSense CE software version 2.9.0. To avoid this panic on that hardware, set a loader tunable for hint.acpi_spmc.0.disabled=1 in /boot/loader.conf.local before upgrading to disable the driver that has an issue on that hardware. See Managing Loader Tunables for information on how to edit or create that file. Release Notes for pfSense CE 2.9.0-RELEASE are available for a more comprehensive list of new features, bug fixes, and other changes in this release. Netgate has a detailed Upgrade Guide available in the pfSense documentation to help explain the process. Below are the high-level steps to perform the upgrade. Upgrades from an earlier version of pfSense CE software are usually made through the web-based user interface. Before any major change, such as an upgrade, the best practice is always to create and securely store a backup of the pfSense configuration. The pfSense documentation contains detailed Backup and Recovery instructions. To perform the update: We encourage users to migrate from pfSense CE software to pfSense Plus software. Doing so will ensure you have access to all of the benefits of pfSense Plus software. You can find details on how to get pfSense Plus software in the Netgate store. Please review the documentation on Troubleshooting Upgrades for the most up-to-date information on working around upgrade issues. This pfSense CE software release is ready for use in production environments. Should any issues arise, please post to our forum or contact Netgate Technical Assistance Center (TAC) for paid assistance. When you purchase Netgate hardware, TAC, or AWS/Azure cloud instances, you directly sustain the engineering teams responsible for maintaining high quality pfSense software. You may support this work through one or more of the following: Our efforts are made possible by the support of our customers and the community, and for that we express our sincere thanks. This involvement makes the pfSense project a stronger solution for everyone.Feature Highlights
SSH Algorithms
TLS Certificate Strength
TLS Certificate Auto-Renew
Endpoint-independent Port Restricted Cone Outbound NAT
Security Updates
Operating System and Base Component Updates
Hardware Errata
Release Notes
Installing the Upgrade
Users currently running pfSense Community Edition (CE) software
Troubleshooting the Upgrade
Supporting the Project