securityaffairs.com 30 Sept 2026, 19:29 UTC

WatchGuard Patches Firebox Flaw That Grants Attackers Root Access

WatchGuard Patches Firebox Flaw That Grants Attackers Root Access
CyberSIXT Evidence Panel Source marked as original reporting

WATCHGUARD has issued security updates for Fireware OS addressing 15 vulnerabilities, including a critical code-injection flaw that could give attackers root access to vulnerable Firebox appliances. The primary issue, CVE-2026-86131, stems from a code injection vulnerability in Fireware OS’s BOVPN Over TLS client configuration handling. An attacker who controls the remote VPN server could execute arbitrary commands as root on the connecting Firebox, with no user interaction or prior privileges required.

BOVPN over TLS uses a client-server model and can transport VPN traffic over TCP port 443, a commonly allowed port, which aids its practicality in restricted network environments.

WatchGuard’s fixes cover Fireware OS releases 2026.3.2, 2026.2.3, 12.12.3 and 12.5.21, with affected branches depending on platform. In addition to CVE-2026-86131, the update patches 13 other high-severity vulnerabilities across Fireware OS components.

Notable examples include CVE-2026-86101, a SAML login authorization flaw that could let a remote authenticated SAML user with access to the Access Portal obtain unauthorized Mobile VPN with SSL access via a crafted request (CVSS 7.2), and CVE-2026-81433, a stack-based buffer overflow in the fingerd DHCP fingerprinting daemon that remote, unauthenticated attackers with adjacent network access could trigger to execute code or crash the service (CVSS 8.7).

WatchGuard states it is not aware of active exploitation in the wild and urges customers to apply the September 29 updates, especially where BOVPN over TLS is enabled.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline