CVE-2026-44693 is a high-severity vulnerability in Pi-hole FTL, a network-level advertisement and tracker blocker. The issue is a race condition in the HTTP session management subsystem, introduced with the v6.0 rewrite of the embedded CivetWeb-based web server. This vulnerability has been patched in version 6.6.1.
CVE-2020-8816 is a Pi-hole AdminLTE remote code execution vulnerability that CISA has listed in its Known Exploited Vulnerabilities catalog. In the supplied record, CISA’s guidance is to apply updates per vendor instructions. Because the issue is in the KEV catalog, defenders should treat it as a prioritized remediation item even though the corpus does not provide version ranges or deeper technical detail.