WatchGuard Patches Critical Fireware OS Code Injection Vulnerability
WatchGuard patched critical Fireware OS code injection that could give remote attackers root on Firebox appliances.
WatchGuard patched 15 Fireware OS vulnerabilities, led by critical code-injection flaw CVE-2026-86131 (CVSS 9.2) in BOVPN-over-TLS client handling. A remote attacker who controls the VPN server could execute commands as root on a connecting Firebox. Fixes are in Fireware OS 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21. Separately, access-point flaws CVE-2026-101891 and CVE-2026-86102, fixed in AP 3.4.8, allow an unauthenticated API session and arbitrary shell commands. WatchGuard says none are known to be exploited.
- CVE-2026-86131 is a CVSS 9.2 code-injection bug in BOVPN over TLS.
- A remote attacker controlling the VPN server can run root commands on Firebox.
- Patches also fix 13 high-severity issues, including unauthenticated remote flaws.
- Access point bugs CVE-2026-101891 and CVE-2026-86102 allow unauthenticated shell commands.
- WatchGuard says it is not aware of in-the-wild exploitation.
Vulnerabilities mentionedAll →
- CVE-2026-1018919.3—Unauthenticated API session flaw in WatchGuard access pointspublished · WatchGuard Access Points
- CVE-2026-861029.3—OS command injection in WatchGuard AP internal APIpublished · WatchGuard AP (internal API service)
Full article287 words · extracted from securityweek.com · click to collapse
WatchGuard on Tuesday announced fixes for 15 vulnerabilities in Fireware OS, including a critical-severity remote code execution (RCE) bug.
Tracked as CVE-2026-86131 (CVSS score of 9.2), the flaw is described as a code injection issue in how the operating system handles BOVPN over TLS client configurations.
Successful exploitation could allow a remote attacker who controls the remote VPN server to execute commands with root privileges on the connecting Firebox appliance.
The security weakness was resolved in Fireware OS versions 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21.
The security updates also resolve 13 high-severity vulnerabilities that could lead to RCE, authorization bypass, denial-of-service (DoS), unauthorized SSLVPN access, and arbitrary local file reads.
A medium-severity improper authorization issue leading to unauthorized access to web applications was also addressed.
Advertisement. Scroll to continue reading.
Several of these security defects could be exploited by remote attackers without authentication.
The Fireware OS patches landed one day after WatchGuard rolled out fixes for two critical- and one high-severity Access Point flaws.
Tracked as CVE-2026-101891 and CVE-2026-86102 and affecting internal API services, the critical issues could be exploited to obtain a valid API session without authentication and execute arbitrary shell commands on the underlying OS.
The high-severity weakness is an OS command injection that requires administrative privileges for exploitation. All three vulnerabilities were resolved in WatchGuard AP version 3.4.8.
According to WatchGuard, it is not aware of any of these security issues being exploited in the wild. Additional information can be found on the company’s security advisories page.
Related: Chrome, Firefox Updates Patch Over 100 Vulnerabilities
Related: Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
Related: Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug
Related: ‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration