WatchGuard patches Fireware OS flaws and endpoint driver bug
WatchGuard patched 15 Fireware OS flaws, including critical root code injection CVE-2026-86131, and sources differ on endpoint driver flaw CVE-2026-13043.
WatchGuard patched 15 Fireware OS vulnerabilities, led by critical code-injection flaw CVE-2026-86131 (CVSS 9.2) in BOVPN-over-TLS client handling. A remote attacker who controls the VPN server can execute commands as root on a connecting Firebox with no user interaction or prior privileges; fixes are in Fireware OS 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21, and WatchGuard says it is not aware of exploitation. Those releases also fix 13 high-severity issues, including SAML authorization bypass CVE-2026-86101 (CVSS 7.2) and DHCP fingerprinting buffer overflow CVE-2026-81433 (CVSS 8.7); separately, access-point flaws CVE-2026-101891 and CVE-2026-86102, fixed in AP 3.4.8, allow an unauthenticated API session and arbitrary shell commands. The Canadian Centre for Cyber Security (AV26-981) warned that CVE-2026-86134, a pre-authentication NULL pointer dereference, can cause remote denial of service in Fireware OS before those four releases, while ZDI disclosed authenticated Fireware remote code execution bugs CVE-2026-18145 (CVSS 7.2, spamd statushdlr stack overflow) and CVE-2026-13046 (CVSS 7.5, samld deserialization requiring session-directory write access), with no exploitation reported. Sources disagree on endpoint flaw CVE-2026-13043: advisory AV26-990 says Endpoint Security before 8.00.26.0012 lacks authentication in a kernel memory-access driver and allows arbitrary kernel memory access, with no exploitation reported, whereas GBHackers rates it CVSS 9.3 in pskmad.sys, says a local authenticated attacker can read kernel and process memory (a proof of concept dumped LSASS on hardened Windows 11 25H2) and that this is information disclosure rather than verified code execution, and says affected and fixed versions were unconfirmed even though Panda said the issue was resolved in October 2026. In a separate ZDI advisory, CVE-2026-50375 (CVSS 8.8) is a time-of-check time-of-use bug in Microsoft Windows dxgkrnl that lets a local attacker who can already run low-privileged code escalate privileges; exploitation in the wild was not reported.
- WatchGuard patched 15 Fireware OS vulnerabilities, led by critical BOVPN-over-TLS code injection CVE-2026-86131 (CVSS 9.2); a remote attacker controlling the VPN server can run root commands on a connecting Firebox with no interaction or…
- Fixes are in Fireware OS 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21; WatchGuard says it is not aware of in-the-wild exploitation.
- The same releases also fix 13 high-severity issues, including SAML authorization bypass CVE-2026-86101 (CVSS 7.2) and DHCP fingerprinting buffer overflow CVE-2026-81433 (CVSS 8.7).
Coverage timelineoldest first · each row is one article
- · 9d agoZDI-26-749: WatchGuard FireWare OS samld SAMLSession Deserialization of Untrusted Data Remote Code Execution Vulnerability
ZDI Published Advisories· 52
WatchGuard Fireware OS samld deserialization flaw CVE-2026-13046 can yield remote code execution after a write precondition.
- · 9d agoZDI-26-750: WatchGuard FireWare OS spamd statushdlr Stack-based Buffer Overflow Remote Code Execution Vulnerability
ZDI Published Advisories· 54
Authenticated stack buffer overflow in WatchGuard Fireware OS spamd allows remote code execution (CVE-2026-18145).
Vulnerabilities in this storyAll →
- CVE-2026-1018919.3—Unauthenticated API session flaw in WatchGuard access pointspublished · WatchGuard Access Points
- CVE-2026-130439.3<1%Missing authentication in WatchGuard PSKMAD kernel driverpublished · WatchGuard Kernel Memory Access Driver (PSKMAD) used by WatchGuard endpoint security products