WatchGuard security advisory (AV26-981)
Canadian Cyber Centre advisory flags CVE-2026-86134, a pre-authentication remote denial-of-service flaw in WatchGuard Fireware OS, urging users to patch.
The Canadian Centre for Cyber Security issued advisory AV26-981 warning that WatchGuard Fireware OS is affected by CVE-2026-86134, a pre-authentication NULL pointer dereference allowing remote denial of service. Affected releases include versions prior to 12.12.3, 12.5.21, 2026.2.3, and 2026.3.2. The Cyber Centre encourages users and administrators to review WatchGuard's security advisories and apply updates as they become available.
- CVE-2026-86134: pre-authentication NULL pointer dereference in Fireware OS enables remote denial of service
- Affected versions: before 12.12.3, 12.5.21, 2026.2.3, and 2026.3.2
- Cyber Centre urges administrators to apply WatchGuard updates
Vulnerabilities mentionedAll →
- CVE-2026-861348.7—Unauthenticated DoS in WatchGuard Fireware OS loginpublished · WatchGuard Fireware OS
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-86134 | Unauthenticated DoS in WatchGuard Fireware OS login CVE-2026-86134 is a NULL pointer dereference (CWE-476) in the authentication process of WatchGuard Fireware OS. A remote, unauthenticated attacker can trigger it by sending a specially crafted request to the login interface, which crashes the management daemon. The impact is denial of service only: availability of the management service is lost, with no confidentiality or integrity impact indicated by the CVSS 4.0 score of 8.7. WatchGuard Fireware OS is affected, but the provided data does not name specific version ranges. There is no known public proof of concept, no report of in-the-wild exploitation, and the CVE is not in the CISA KEV catalog. Do: Keep the Fireware OS management and login interface off the public internet and allow it only from trusted admin networks or a VPN. Apply WatchGuard’s security update for CVE-2026-86134 as soon as a fixed Fireware OS build is available, and watch for unexpected management-daemon crashes or restarts. No public exploit is known and the issue is not listed in CISA KEV. |
Full article74 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-981
Date: October 1, 2026
As of September 30, 2026, WatchGuard is affected by a vulnerability in the following product:
- Fireware OS
- Prior to 12.12.3
- Prior to 12.5.21
- Prior to 2026.2.3
- Prior to 2026.3.2
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/watchguard-security-advisory-av26-981