WatchGuard fixes critical Fireware OS flaw allowing remote code execution
WatchGuard patched 15 Fireware OS bugs, including critical root RCE CVE-2026-86131 on Firebox VPN clients.
WatchGuard released Fireware OS updates fixing 15 vulnerabilities, including critical code-injection flaw CVE-2026-86131 (CVSS 9.2). An attacker who controls the remote BOVPN-over-TLS server can execute arbitrary commands as root on a connecting Firebox, with no user interaction or prior privileges. Patches are in Fireware OS 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21. The same releases also fix high-severity issues including SAML authorization bypass CVE-2026-86101 (CVSS 7.2) and DHCP fingerprinting buffer overflow CVE-2026-81433 (CVSS 8.7). WatchGuard said it is not aware of exploitation in the wild.
- CVE-2026-86131 (CVSS 9.2) lets a malicious VPN server run root commands on a Firebox.
- Attacker must control the remote BOVPN-over-TLS server; no interaction or prior privileges needed.
- Also patched: SAML bypass CVE-2026-86101 and DHCP overflow CVE-2026-81433 among 13 high-severity bugs.
- Fixed in Fireware OS 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21; no known exploitation.
Vulnerabilities mentionedAll →
- CVE-2026-814338.7—Stack buffer overflow in WatchGuard Fireware OS DHCP fingerdpublished · WatchGuard Fireware OS (DHCP fingerprinting daemon fingerd)
- CVE-2026-861319.2—Root code injection in WatchGuard Fireware BOVPN Over TLSpublished · WatchGuard Fireware OS+1 related
| CVE | Vulnerability |
|---|
Full article542 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
September 30, 2026

WatchGuard fixes 15 Fireware OS flaws, including a critical RCE bug that could give attackers root access to vulnerable Firebox appliances.
WatchGuard has released security updates for Fireware OS that address 15 vulnerabilities, including a critical code injection flaw, tracked as CVE-2026-86131 (CVSS score of 9.2), that could allow an attacker to execute commands with root privileges on a vulnerable Firebox.
“A code injection vulnerability in WatchGuard Fireware OS’s BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.” reads the advisory.
The flaw affects the way Fireware OS handles configurations for BOVPN over TLS clients, a feature used to create VPN tunnels between WatchGuard Firebox appliances.
The attack requires the threat actor to control the remote VPN server to which the vulnerable Firebox connects. If successfully exploited, the attacker can execute arbitrary commands as root on the connecting appliance. The vulnerability does not require user interaction or prior privileges.
BOVPN over TLS uses a client-server model and can send VPN traffic over TCP port 443, a port commonly allowed through network firewalls. This makes the feature useful in environments where traditional IPsec traffic cannot easily pass through the network.
WatchGuard addressed CVE-2026-86131 in Fireware OS 2026.3.2, 2026.2.3, 12.12.3 and 12.5.21. The affected branches include Fireware versions below those releases, depending on the platform.
The vendor also addresses 13 high-severity vulnerabilities affecting different Fireware OS components. The flaws include vulnerabilities that could lead to remote code execution, authorization bypass, denial-of-service conditions, unauthorized SSLVPN access and arbitrary file reads.
One example is CVE-2026-86101 (CVSS score of 7.2), a high-severity authorization flaw in the SAML login process. A remote authenticated SAML user with access to the Access Portal could abuse a specially crafted request to obtain unauthorized Mobile VPN with SSL access.
“An improper authorization vulnerability in WatchGuard Fireware OS’s SAML login process allows a remote, authenticated SAML user with access only to the Access Portal to obtain unauthorized Mobile VPN with SSL access through a specially crafted request.” states the advisory.
WatchGuard fixed the issue in the same Fireware OS releases.
Another patched issue allows an attacker with adjacent network access to send specially crafted DHCP traffic that can trigger a stack-based buffer overflow in the fingerd process. The flaw, tracked as CVE-2026-81433 (CVSS score of 8.7), can lead to arbitrary code execution or a crash.
“A stack-based buffer overflow vulnerability in WatchGuard Fireware OS’s DHCP fingerprinting daemon (fingerd) allows an unauthenticated attacker with adjacent network access to execute arbitrary code or crash the process by sending a specially crafted DHCP packet.” the company states.
The update also includes a medium-severity authorization issue that could allow unauthorized access to web applications.
The vendor pointed out it is not aware of exploitation of these Fireware OS vulnerabilities in the wild. The company has published the fixes and recommends customers update affected Firebox appliances to the appropriate patched release.
Organizations using Firebox appliances should therefore review their Fireware OS versions and prioritize the September 29 security updates, particularly where BOVPN over TLS is enabled.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Fireware OS)