PatchSiren

pi-hole CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH pi-hole CVE published 2026-06-10

CVE-2026-44693

CVE-2026-44693 is a high-severity vulnerability in Pi-hole FTL, a network-level advertisement and tracker blocker. The issue is a race condition in the HTTP session management subsystem, introduced with the v6.0 rewrite of the embedded CivetWeb-based web server. This vulnerability has been patched in version 6.6.1.

Known exploited Pi-hole CVE published 2021-12-10

CVE-2020-8816

CVE-2020-8816 is a Pi-hole AdminLTE remote code execution vulnerability that CISA has listed in its Known Exploited Vulnerabilities catalog. In the supplied record, CISA’s guidance is to apply updates per vendor instructions. Because the issue is in the KEV catalog, defenders should treat it as a prioritized remediation item even though the corpus does not provide version ranges or deeper technical detail.