WatchGuard has issued fixes for 15 Fireware OS vulnerabilities, headlined by CVE-2026-86131, a critical code injection flaw with a CVSS score of 9.2. A remote operator of a malicious VPN endpoint could gain root-level command execution on a connecting Firebox appliance. Patched releases are now available in four supported branches, with no in-the-wild exploitation reported.
How the critical flaw works
CVE-2026-86131 affects handling of BOVPN over TLS client configurations in Fireware OS. When a Firebox appliance connects to a remote VPN server under attacker control, that remote side can trigger injected code that runs with root privileges on the connecting appliance.
Fixed builds are Fireware OS versions 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21.
Other Fireware OS issues corrected
The same Fireware OS update addresses 13 high-severity weaknesses covering code execution, authorization, DoS, and path traversal. Their impacts include RCE, authorization bypass, denial-of-service (DoS), unauthorized SSLVPN access, and arbitrary local file reads.
One additional medium-severity improper authorization flaw was corrected, which allowed unauthorized access to web applications. Several of the defects are reachable by remote attackers without authentication.
Access Point flaws patched a day earlier
The Fireware OS release followed by one day a separate update for WatchGuard Access Point flaws covering two critical- and one high-severity issues.
The two critical issues, tracked as CVE-2026-101891 and CVE-2026-86102, affect internal API services. They allow obtaining a valid API session without authentication and executing arbitrary shell commands on the underlying OS. The remaining high-severity issue is an OS command injection that requires administrative privileges for exploitation.
All three Access Point vulnerabilities were resolved in WatchGuard AP version 3.4.8.
Technical background
This section describes the vulnerability class in general terms only and does not describe the WatchGuard exploit, for which no PoC was included in the supplied material.
VPN clients often consume profiles, hostnames, routes, and TLS parameters supplied by a server or configuration file. If those values are concatenated into system commands or interpreted without strict validation, a malicious server can break out of the intended field and inject operating-system commands that then run with the privileges of the VPN service, in the worst case as root.
Illustrative generic pattern only, not vendor code:
# GENERIC EXAMPLE - unsafe: untrusted value expanded in shell
eval "vpn-setup --remote $REMOTE_HOST --route $REMOTE_ROUTE"
# GENERIC EXAMPLE - safer approach: avoid shell, validate and pass as argv
vpn-setup --remote="$validated_host" --route="$validated_route"
Defenses for this class generally include allow-list validation of hostnames and configuration fields, avoiding shell invocation, running VPN helpers with least privilege, and separating parsing from privileged execution.
Detection and mitigation
Administrators should upgrade Fireware OS to 2026.3.2, 2026.2.3, 12.12.3, or 12.5.21 depending on their track, and upgrade Access Point deployments to 3.4.8. Prioritize externally facing Firebox systems that initiate BOVPN over TLS connections to less-trusted peers, and review configurations for unexpected peers or client profiles.
According to WatchGuard, it is not aware of any of these security issues being exploited in the wild. Additional information can be found on the company's security advisories page.