WATCHGUARD has issued patches for 15 vulnerabilities across Fireware OS, including a highly critical remote code execution flaw tracked as CVE-2026-86131 (CVSS 9.2). The code-injection weakness affects how Fireware OS handles BOVPN over TLS client configurations, potentially enabling a remote attacker who controls the VPN server to run commands with root privileges on a Firebox appliance. Fireware OS fixes are delivered in versions 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21.
In addition to the RCE, the release closes 13 high-severity flaws that could lead to RCE, bypass of authorisation, DoS, unauthorized SSLVPN access, and arbitrary local file reads. A medium-severity improper authorisation issue was also addressed, which could permit unauthorized web-application access.
WatchGuard notes that several defects could be exploited remotely without authentication. Separately, the company previously patched two critical- and one high-severity Access Point vulnerabilities in AP version 3.4.8, tracked as CVE-2026-101891 and CVE-2026-86102, which could allow an unauthenticated API session and arbitrary shell commands on the underlying OS, with the high-severity OS command-injection requiring administrative privileges. WatchGuard says it is not aware of any of these issues being exploited in the wild, and directs readers to its PSIRT advisories for further details.