WatchGuard fixes critical Fireware OS flaw allowing remote code execution
WatchGuard patched 15 Fireware OS bugs, including critical root RCE CVE-2026-86131 on Firebox VPN clients.
WatchGuard released Fireware OS updates fixing 15 vulnerabilities, including critical code-injection flaw CVE-2026-86131 (CVSS 9.2). An attacker who controls the remote BOVPN-over-TLS server can execute arbitrary commands as root on a connecting Firebox, with no user interaction or prior privileges. Patches are in Fireware OS 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21. The same releases also fix high-severity issues including SAML authorization bypass CVE-2026-86101 (CVSS 7.2) and DHCP fingerprinting buffer overflow CVE-2026-81433 (CVSS 8.7). WatchGuard said it is not aware of exploitation in the wild.