Question re: pkg vulnerabilities

What is the fastest (and safest for production) way to get the fixed version of a package that has vulnerabilities?

For example, I'm running 14.3-p5 and a somewhat recent package audit yielded the following:

apache24-2.4.65_1 is vulnerable:
Apache httpd -- Multiple vulnerabilities
CVE: CVE-2025-55753
CVE: CVE-2025-58098
CVE: CVE-2025-59775
CVE: CVE-2025-65082
CVE: CVE-2025-66200
WWW: https://vuxml.freebsd.org/freebsd/6ebe4a30-d138-11f0-af8c-8447094a420f.html

Heading to the above listed page, I can see that an updated version has been released:

Fixed in Apache HTTP Server 2.4.66​

Checking the version of apache24 on the latest branch, I see that there is an updated package:

Installed packages to be UPGRADED:
apache24: 2.4.65_1 -> 2.4.66 [FreeBSD

Is tracking the latest branch instead of the quarterly branch the only to get this security fix quickly and/or safely? Or, am I missing some other more appropriate method to achieve the same goal for a production server? I have always admired and relied on FreeBSD's stability and don't want to sacrifice that if it can be avoided. However, the idea that I may have to go as long as 3 months before getting a security fix on my server that was fixed long before that doesn't seem acceptable either.

Thanks in advance!
 
No, as I understand the policy security fixes are brought over to quarterly. It just can take a little more time since you don't want to update up or down dependencies.

At the time of this writing no commit has been made to 2025Q4.
 
You can see in the head commit that merging to Q4 is intended.

Code:
commit 623207ecebde609e40edac8bada7e4c4c026e4d2
Author:     Bernard Spil <brnrd@FreeBSD.org>
AuthorDate: Fri Dec 5 13:13:14 2025 +0100
Commit:     Bernard Spil <brnrd@FreeBSD.org>
CommitDate: Fri Dec 5 13:13:14 2025 +0100

    www/apache24: Security update to 2.4.66
    
    PR:             291413
    Security:       6ebe4a30-d138-11f0-af8c-8447094a420f
    MFH:            2025Q4
 
Back
Top