WATCHGUARD has released patches for 14 vulnerabilities in its Fireware OS, affecting Firebox firewalls. The most severe flaw is CVE-2026-86131, a code injection vulnerability in the BOVPN Over TLS client that can enable remote code execution with a CVSS v4 score of 9.2. Other notable issues include CVE-2026-81433, a pre-authentication stack buffer overflow in fingerd (CVSS 8.7), along with several denial-of-service and pre-authentication flaws. WatchGuard notes that many of the flaws can be triggered without logging in, highlighting the risk to edge devices that terminate VPN connections.
Affected products cover Fireware OS across 12.x, 2025.x, and 2026.x lines, with precise exposure varying by CVE. The vendor states there is no known exploitation in the wild for these issues. The article lists the top CVEs and their fixed versions, including 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21 as patched releases, while EUCC customers on 12.11 should move to 12.11.10. Each vulnerability has an entry on the WatchGuard PSIRT portal.
In the interim, administrators are advised to restrict management Web UI and Access Portal access to trusted networks and review BOVPN Over TLS and IKEv2 VPN peer configurations to reduce exposure.