AI analysis
CVE-2026-86134 is a NULL pointer dereference (CWE-476) in the authentication process of WatchGuard Fireware OS. A remote, unauthenticated attacker can trigger it by sending a specially crafted request to the login interface, which crashes the management daemon. The impact is denial of service only: availability of the management service is lost, with no confidentiality or integrity impact indicated by the CVSS 4.0 score of 8.7. WatchGuard Fireware OS is affected, but the provided data does not name specific version ranges. There is no known public proof of concept, no report of in-the-wild exploitation, and the CVE is not in the CISA KEV catalog.
What to do: Keep the Fireware OS management and login interface off the public internet and allow it only from trusted admin networks or a VPN. Apply WatchGuard’s security update for CVE-2026-86134 as soon as a fixed Fireware OS build is available, and watch for unexpected management-daemon crashes or restarts. No public exploit is known and the issue is not listed in CISA KEV.
Estimated exposure
largeOn the order of 10,000–100,000 internet-exposed WatchGuard management interfaces (estimate; vulnerable subset unknown) — WatchGuard firewalls are widely deployed in SMB and mid-market networks, and historical public internet scans have typically shown on the order of tens of thousands of reachable Firebox management services; this advisory does not state…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A NULL pointer dereference vulnerability in the WatchGuard Fireware OS authentication process allows a remote, unauthenticated attacker to crash the management daemon by sending a specially request to the login interface, resulting in a denial of service.