FreeBSD released security updates for 22 vulnerabilities across the operating system, including multiple flaws that could lead to remote code execution, local privilege escalation to root, denial of service, memory corruption, and information disclosure. The most severe issue, CVE-2026-49420, affects libalias, where improper handling of RTSP traffic during NAT processing can allow remote code execution as root on systems using ipfw NAT or natd.
The fixes were shipped in FreeBSD 15.1-RELEASE-p1, 15.0-RELEASE-p11, 14.4-RELEASE-p7, and 14.3-RELEASE-p16. Additional patched components include execve, Jail, OpenZFS, Linuxulator, KTLS, sound, vt, ptrace, IPv6 multicast filtering, tcp_rack, compat32, iconv, and pathname resolution protections such as AT_RESOLVE_BENEATH, with the advisory noting that 13 of the issues could enable privilege escalation to root.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Fixes for the disclosed vulnerabilities were released in FreeBSD 15.1-RELEASE-p1, 15.0-RELEASE-p11, 14.4-RELEASE-p7, and 14.3-RELEASE-p16. The patched issues affected components including execve, Jail, OpenZFS, Linuxulator, KTLS, sound, vt, ptrace, IPv6 multicast filtering, tcp_rack, compat32, iconv, and pathname resolution protections.
FreeBSD published a security advisory covering 22 vulnerabilities, including issues that could lead to remote code execution, local privilege escalation, denial of service, memory corruption, and information disclosure. The most serious issue highlighted was CVE-2026-49420 in libalias, involving unsafe RTSP handling in NAT-related functionality that could allow remote code execution as root via ipfw NAT or natd.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.