CVE-2026-86128: CWE-476 in WatchGuard Fireware OS
CVE-2026-86128 is a high-severity NULL pointer dereference vulnerability in WatchGuard Fireware OS affecting its NetFlow packet-processing feature. A remote, unauthenticated attacker can cause a denial of service by sending a specially crafted IPv6 packet. This vulnerability impacts multiple Fireware OS versions prior to specific patch releases.
AI Analysis
Technical Summary
This vulnerability (CWE-476) in WatchGuard Fireware OS arises from improper handling of NetFlow packets, specifically when processing IPv6 packets. The flaw allows a remote attacker without authentication to trigger a NULL pointer dereference, leading to a denial of service condition. The affected versions include Fireware OS releases from 12.0 up to but not including 12.5.21 and 12.12.3, as well as versions from 2025.0 up to but not including 2026.2.3 and 2026.3 up to but not including 2026.3.2. The CVSS 4.0 base score is 8.2, indicating high severity with network attack vector, low complexity, no privileges or user interaction required, and high impact on availability.
Potential Impact
Successful exploitation results in denial of service of the Fireware OS device due to a NULL pointer dereference triggered by a crafted IPv6 packet. This can disrupt network operations relying on the affected device. There is no indication of code execution or data breach from this vulnerability. No known exploits are reported in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until official patches are available, consider disabling or restricting access to the NetFlow packet-processing feature if feasible to reduce exposure. Monitor vendor communications for updates on fixes.
CVE-2026-86128: CWE-476 in WatchGuard Fireware OS
Description
CVE-2026-86128 is a high-severity NULL pointer dereference vulnerability in WatchGuard Fireware OS affecting its NetFlow packet-processing feature. A remote, unauthenticated attacker can cause a denial of service by sending a specially crafted IPv6 packet. This vulnerability impacts multiple Fireware OS versions prior to specific patch releases.
CVSS v4.0
Score 8.2high
Affected software
WatchGuard
Fireware OS
WatchGuard
Fireware OS
pkg:github/watchguard/fireware-osRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CWE-476) in WatchGuard Fireware OS arises from improper handling of NetFlow packets, specifically when processing IPv6 packets. The flaw allows a remote attacker without authentication to trigger a NULL pointer dereference, leading to a denial of service condition. The affected versions include Fireware OS releases from 12.0 up to but not including 12.5.21 and 12.12.3, as well as versions from 2025.0 up to but not including 2026.2.3 and 2026.3 up to but not including 2026.3.2. The CVSS 4.0 base score is 8.2, indicating high severity with network attack vector, low complexity, no privileges or user interaction required, and high impact on availability.
Potential Impact
Successful exploitation results in denial of service of the Fireware OS device due to a NULL pointer dereference triggered by a crafted IPv6 packet. This can disrupt network operations relying on the affected device. There is no indication of code execution or data breach from this vulnerability. No known exploits are reported in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until official patches are available, consider disabling or restricting access to the NetFlow packet-processing feature if feasible to reduce exposure. Monitor vendor communications for updates on fixes.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WatchGuard
- Date Reserved
- 2026-09-05T02:33:08.986Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6abc4826680226ef686df2c9
Added to database: 09/29/2026, 23:22:14 UTC
Last enriched: 09/29/2026, 23:36:34 UTC
Last updated: 09/29/2026, 23:49:36 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.