Skip to content

WatchGuard Technologies Fireware OS: code injection

Critical9.2CVE-2026-86131 · Published Sep 30, 2026 · updated Oct 1, 2026

A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.

Affected versions

PackageAffectedFixed in
Fireware OS
Product
>= 2026.3, < 2026.3.22026.3.2
>= 2025.0, < 2026.2.32026.2.3
>= 12.0, < 12.12.312.12.3
>= 12.0, < 12.5.2112.5.21
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-94, CWE-295, CWE-829

More WatchGuard Technologies advisories

All WatchGuard Technologies
Advisory
WatchGuard Technologies Fireware OS: null pointer dereference
High8.7Sep 30
WatchGuard Technologies Fireware OS: integer overflow
High8.2Sep 30
WatchGuard Technologies Fireware OS: missing authorization
High7.1Sep 30
WatchGuard Technologies Fireware OS: missing authorization
High7.1Sep 30
WatchGuard Technologies Fireware OS: stack buffer overflow
High8.6Sep 30
WatchGuard Technologies Fireware OS: stack buffer overflow
High8.7Sep 30

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.