Skip to main content

WatchGuard Patches Critical Fireware OS Code Injection Vulnerability

0
Critical
Vulnerability
Published: 09/30/2026 (09/30/2026, 13:16:56 UTC)
Source: SecurityWeek

Description

WatchGuard released patches for 15 vulnerabilities in Fireware OS, including a critical remote code execution (RCE) vulnerability (CVE-2026-86131) involving code injection via BOVPN over TLS client configurations. Exploitation could allow remote attackers controlling a VPN server to execute commands with root privileges on Firebox appliances. The update also addresses 13 other high-severity issues such as RCE, authorization bypass, denial-of-service, unauthorized SSLVPN access, and arbitrary local file reads, plus a medium-severity improper authorization flaw. Additional critical and high-severity vulnerabilities affecting WatchGuard Access Points were patched in version 3.4.8. No exploitation in the wild is currently known.

Affected software

Affected versions
>=2026.2.3 <=2026.3.1>=12.5.0 <=12.5.20>=12.12.0 <=12.12.2<3.4.8

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/30/2026, 13:18:28 UTC

Technical Analysis

WatchGuard patched 15 vulnerabilities in Fireware OS, including a critical code injection flaw (CVE-2026-86131) with a CVSS score of 9.2. This vulnerability arises from improper handling of BOVPN over TLS client configurations, allowing remote attackers controlling the VPN server to execute commands as root on Firebox appliances. The patches also fix 13 high-severity bugs enabling remote code execution, authorization bypass, denial-of-service, unauthorized SSLVPN access, and arbitrary local file reads, plus a medium-severity improper authorization issue. Separately, critical and high-severity vulnerabilities in WatchGuard Access Points were fixed in version 3.4.8, including unauthenticated API session acquisition and OS command injection. WatchGuard is not aware of any active exploitation of these vulnerabilities.

Potential Impact

Successful exploitation of CVE-2026-86131 could allow remote attackers controlling a VPN server to execute arbitrary commands with root privileges on Firebox appliances, potentially leading to full system compromise. Other vulnerabilities patched include those enabling remote code execution, denial-of-service, authorization bypass, unauthorized access to SSLVPN, and local file read attacks. The Access Point vulnerabilities could allow unauthenticated attackers to obtain valid API sessions or execute shell commands, increasing risk of device compromise. No known exploitation in the wild has been reported.

Mitigation Recommendations

WatchGuard has released official patches resolving these vulnerabilities in Fireware OS versions 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21, and in WatchGuard Access Point version 3.4.8. Users should apply these updates promptly to mitigate risk. There are no reports of active exploitation, but timely patching is recommended to prevent potential attacks.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.95,"severitySource":"heuristic","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/watchguard-patches-critical-fireware-os-code-injection-vulnerability/","fetched":true,"fetchedAt":"2026-09-30T13:18:21.074Z","wordCount":944}

Threat ID: 6abd0c1d2a4e24523d0ad785

Added to database: 09/30/2026, 13:18:21 UTC

Last enriched: 09/30/2026, 13:18:28 UTC

Last updated: 09/30/2026, 14:16:58 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses