WatchGuard Patches Critical Fireware OS Code Injection Vulnerability
WatchGuard released patches for 15 vulnerabilities in Fireware OS, including a critical remote code execution (RCE) vulnerability (CVE-2026-86131) involving code injection via BOVPN over TLS client configurations. Exploitation could allow remote attackers controlling a VPN server to execute commands with root privileges on Firebox appliances. The update also addresses 13 other high-severity issues such as RCE, authorization bypass, denial-of-service, unauthorized SSLVPN access, and arbitrary local file reads, plus a medium-severity improper authorization flaw. Additional critical and high-severity vulnerabilities affecting WatchGuard Access Points were patched in version 3.4.8. No exploitation in the wild is currently known.
AI Analysis
Technical Summary
WatchGuard patched 15 vulnerabilities in Fireware OS, including a critical code injection flaw (CVE-2026-86131) with a CVSS score of 9.2. This vulnerability arises from improper handling of BOVPN over TLS client configurations, allowing remote attackers controlling the VPN server to execute commands as root on Firebox appliances. The patches also fix 13 high-severity bugs enabling remote code execution, authorization bypass, denial-of-service, unauthorized SSLVPN access, and arbitrary local file reads, plus a medium-severity improper authorization issue. Separately, critical and high-severity vulnerabilities in WatchGuard Access Points were fixed in version 3.4.8, including unauthenticated API session acquisition and OS command injection. WatchGuard is not aware of any active exploitation of these vulnerabilities.
Potential Impact
Successful exploitation of CVE-2026-86131 could allow remote attackers controlling a VPN server to execute arbitrary commands with root privileges on Firebox appliances, potentially leading to full system compromise. Other vulnerabilities patched include those enabling remote code execution, denial-of-service, authorization bypass, unauthorized access to SSLVPN, and local file read attacks. The Access Point vulnerabilities could allow unauthenticated attackers to obtain valid API sessions or execute shell commands, increasing risk of device compromise. No known exploitation in the wild has been reported.
Mitigation Recommendations
WatchGuard has released official patches resolving these vulnerabilities in Fireware OS versions 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21, and in WatchGuard Access Point version 3.4.8. Users should apply these updates promptly to mitigate risk. There are no reports of active exploitation, but timely patching is recommended to prevent potential attacks.
WatchGuard Patches Critical Fireware OS Code Injection Vulnerability
Description
WatchGuard released patches for 15 vulnerabilities in Fireware OS, including a critical remote code execution (RCE) vulnerability (CVE-2026-86131) involving code injection via BOVPN over TLS client configurations. Exploitation could allow remote attackers controlling a VPN server to execute commands with root privileges on Firebox appliances. The update also addresses 13 other high-severity issues such as RCE, authorization bypass, denial-of-service, unauthorized SSLVPN access, and arbitrary local file reads, plus a medium-severity improper authorization flaw. Additional critical and high-severity vulnerabilities affecting WatchGuard Access Points were patched in version 3.4.8. No exploitation in the wild is currently known.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
WatchGuard patched 15 vulnerabilities in Fireware OS, including a critical code injection flaw (CVE-2026-86131) with a CVSS score of 9.2. This vulnerability arises from improper handling of BOVPN over TLS client configurations, allowing remote attackers controlling the VPN server to execute commands as root on Firebox appliances. The patches also fix 13 high-severity bugs enabling remote code execution, authorization bypass, denial-of-service, unauthorized SSLVPN access, and arbitrary local file reads, plus a medium-severity improper authorization issue. Separately, critical and high-severity vulnerabilities in WatchGuard Access Points were fixed in version 3.4.8, including unauthenticated API session acquisition and OS command injection. WatchGuard is not aware of any active exploitation of these vulnerabilities.
Potential Impact
Successful exploitation of CVE-2026-86131 could allow remote attackers controlling a VPN server to execute arbitrary commands with root privileges on Firebox appliances, potentially leading to full system compromise. Other vulnerabilities patched include those enabling remote code execution, denial-of-service, authorization bypass, unauthorized access to SSLVPN, and local file read attacks. The Access Point vulnerabilities could allow unauthenticated attackers to obtain valid API sessions or execute shell commands, increasing risk of device compromise. No known exploitation in the wild has been reported.
Mitigation Recommendations
WatchGuard has released official patches resolving these vulnerabilities in Fireware OS versions 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21, and in WatchGuard Access Point version 3.4.8. Users should apply these updates promptly to mitigate risk. There are no reports of active exploitation, but timely patching is recommended to prevent potential attacks.
Technical Details
- Classification
- {"confidence":0.95,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/watchguard-patches-critical-fireware-os-code-injection-vulnerability/","fetched":true,"fetchedAt":"2026-09-30T13:18:21.074Z","wordCount":944}
Threat ID: 6abd0c1d2a4e24523d0ad785
Added to database: 09/30/2026, 13:18:21 UTC
Last enriched: 09/30/2026, 13:18:28 UTC
Last updated: 09/30/2026, 14:16:58 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.