www.securityweek.com 30 Sept 2026, 13:16 UTC

WatchGuard Patches Critical Firebox Flaw Enabling Root RCE

WatchGuard Patches Critical Firebox Flaw Enabling Root RCE
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Not in KEV
Patch Patch Status Unknown

WATCHGUARD has issued patches for 15 vulnerabilities across Fireware OS, including a highly critical remote code execution flaw tracked as CVE-2026-86131 (CVSS 9.2). The code-injection weakness affects how Fireware OS handles BOVPN over TLS client configurations, potentially enabling a remote attacker who controls the VPN server to run commands with root privileges on a Firebox appliance. Fireware OS fixes are delivered in versions 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21.

In addition to the RCE, the release closes 13 high-severity flaws that could lead to RCE, bypass of authorisation, DoS, unauthorized SSLVPN access, and arbitrary local file reads. A medium-severity improper authorisation issue was also addressed, which could permit unauthorized web-application access.

WatchGuard notes that several defects could be exploited remotely without authentication. Separately, the company previously patched two critical- and one high-severity Access Point vulnerabilities in AP version 3.4.8, tracked as CVE-2026-101891 and CVE-2026-86102, which could allow an unauthenticated API session and arbitrary shell commands on the underlying OS, with the high-severity OS command-injection requiring administrative privileges. WatchGuard says it is not aware of any of these issues being exploited in the wild, and directs readers to its PSIRT advisories for further details.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline