Hello, hello,

Yes, we are obviously still alive! This update addresses a number of security issues -- first and foremost an injection into LDAP authentication that can bypass group restrictions during login. Also included are Curl and OpenSSL third party updates as well as FreeBSD security advisories.

Further UX tweaks reached the new firewall rules GUI, the MVC grid system and surprising movement in the Kea corner. But maybe most importantly: the captive portal finally gained native IPv6 support. Let us know what you think about it!

Here are the full patch notes:

A hotfix release was issued as 26.1.6_2:


Stay safe,
Your OPNsense team

SHA256 (OPNsense-26.1.6-dvd-amd64.iso.bz2) = 6ba3633d9c0f96d82c792015a45f4b8aac45ea8fa2bdba3c5e534d0c90a4f08c
SHA256 (OPNsense-26.1.6-nano-amd64.img.bz2) = 3c16267c791abfc3e41d5249fcb0c245c03cb91e2f1aa4d53017f0f3454d03a1
SHA256 (OPNsense-26.1.6-serial-amd64.img.bz2) = 60e698b7f935b647b72a424c78acaa1772a050bb4bd593ca001ea9a1634d5643
SHA256 (OPNsense-26.1.6-vga-amd64.img.bz2) = cf8deca3033b66138930d417c879cb93b7930d1ca8dabd7e1aea914f9a551f4a