WatchGuard fixes critical Fireware OS flaw allowing remote code execution

Pierluigi Paganini September 30, 2026

WatchGuard fixes 15 Fireware OS flaws, including a critical RCE bug that could give attackers root access to vulnerable Firebox appliances.

WatchGuard has released security updates for Fireware OS that address 15 vulnerabilities, including a critical code injection flaw, tracked as CVE-2026-86131 (CVSS score of 9.2), that could allow an attacker to execute commands with root privileges on a vulnerable Firebox.

“A code injection vulnerability in WatchGuard Fireware OS’s BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.” reads the advisory.

The flaw affects the way Fireware OS handles configurations for BOVPN over TLS clients, a feature used to create VPN tunnels between WatchGuard Firebox appliances.

The attack requires the threat actor to control the remote VPN server to which the vulnerable Firebox connects. If successfully exploited, the attacker can execute arbitrary commands as root on the connecting appliance. The vulnerability does not require user interaction or prior privileges.

BOVPN over TLS uses a client-server model and can send VPN traffic over TCP port 443, a port commonly allowed through network firewalls. This makes the feature useful in environments where traditional IPsec traffic cannot easily pass through the network.

WatchGuard addressed CVE-2026-86131 in Fireware OS 2026.3.2, 2026.2.3, 12.12.3 and 12.5.21. The affected branches include Fireware versions below those releases, depending on the platform.

The vendor also addresses 13 high-severity vulnerabilities affecting different Fireware OS components. The flaws include vulnerabilities that could lead to remote code execution, authorization bypass, denial-of-service conditions, unauthorized SSLVPN access and arbitrary file reads.

One example is CVE-2026-86101 (CVSS score of 7.2), a high-severity authorization flaw in the SAML login process. A remote authenticated SAML user with access to the Access Portal could abuse a specially crafted request to obtain unauthorized Mobile VPN with SSL access.

“An improper authorization vulnerability in WatchGuard Fireware OS’s SAML login process allows a remote, authenticated SAML user with access only to the Access Portal to obtain unauthorized Mobile VPN with SSL access through a specially crafted request.” states the advisory.

WatchGuard fixed the issue in the same Fireware OS releases.

Another patched issue allows an attacker with adjacent network access to send specially crafted DHCP traffic that can trigger a stack-based buffer overflow in the fingerd process. The flaw, tracked as CVE-2026-81433 (CVSS score of 8.7), can lead to arbitrary code execution or a crash.

“A stack-based buffer overflow vulnerability in WatchGuard Fireware OS’s DHCP fingerprinting daemon (fingerd) allows an unauthenticated attacker with adjacent network access to execute arbitrary code or crash the process by sending a specially crafted DHCP packet.” the company states.

The update also includes a medium-severity authorization issue that could allow unauthorized access to web applications.

The vendor pointed out it is not aware of exploitation of these Fireware OS vulnerabilities in the wild. The company has published the fixes and recommends customers update affected Firebox appliances to the appropriate patched release.

Organizations using Firebox appliances should therefore review their Fireware OS versions and prioritize the September 29 security updates, particularly where BOVPN over TLS is enabled.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Fireware OS)



you might also like

leave a comment