WatchGuard Patches Critical Fireware OS Code Injection Vulnerability
WatchGuard patched critical Fireware OS code injection that could give remote attackers root on Firebox appliances.
WatchGuard patched 15 Fireware OS vulnerabilities, led by critical code-injection flaw CVE-2026-86131 (CVSS 9.2) in BOVPN-over-TLS client handling. A remote attacker who controls the VPN server could execute commands as root on a connecting Firebox. Fixes are in Fireware OS 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21. Separately, access-point flaws CVE-2026-101891 and CVE-2026-86102, fixed in AP 3.4.8, allow an unauthenticated API session and arbitrary shell commands. WatchGuard says none are known to be exploited.