Skip to content

WatchGuard patches critical Fireware OS RCE (CVE-2026-86131)

WatchGuard fixed CVE-2026-86131 (CVSS 9.2), a code-injection flaw letting a malicious BOVPN-over-TLS server run root commands on a connecting Firebox, plus 13 more high-severity Fireware OS bugs.

Published 2 min read

WatchGuard has patched CVE-2026-86131, a CVSS 9.2 code-injection flaw in Fireware OS that lets an attacker who controls a BOVPN-over-TLS server execute commands with root privileges on the Firebox appliance that connects to it. It's the headline of a batch that fixes more than a dozen Fireware OS vulnerabilities.

The primary reference is WatchGuard's PSIRT advisory portal; the flaw is tracked at CVE-2026-86131.

What's affected

The bug is in how Fireware OS handles Branch Office VPN (BOVPN) over TLS client configurations. Exploitation requires the Firebox to connect, as a client, to a VPN server the attacker controls — so the practical prerequisite is control (or spoofing) of the remote BOVPN-over-TLS peer, not an unauthenticated hit against the box's public interface. Where that condition is met, the payload runs as root.

Fixed builds:

  • Fireware OS 2026.3.2
  • Fireware OS 2026.2.3
  • Fireware OS 12.12.3
  • Fireware OS 12.5.21

WatchGuard's release resolves 13 additional high-severity issues — further RCE, authorization bypass, denial of service, unauthorized SSLVPN access, and arbitrary local file read — plus one medium-severity improper-authorization flaw.

Exploitation status

None reported. WatchGuard states it is "not aware of any of these security issues being exploited in the wild." No public PoC has surfaced.

Action checklist

  1. Upgrade Fireware OS to 2026.3.2, 2026.2.3, 12.12.3, or 12.5.21 depending on your branch. Firebox appliances are perimeter devices — treat this as a same-cycle patch.
  2. Prioritize appliances that initiate BOVPN-over-TLS tunnels, especially hub-and-spoke deployments where a branch Firebox dials into a central endpoint.
  3. Validate the identity of BOVPN-over-TLS peers. Since exploitation hinges on the appliance connecting to a hostile server, confirm tunnel endpoints and certificates are what you expect.
  4. Review SSLVPN exposure given the additional high-severity SSLVPN and file-read fixes in the same release.

Context

Firewall and VPN appliances remain among the most heavily targeted classes of edge device, and Fireboxes are no exception — network gear that terminates VPN tunnels sits exactly where attackers want a root shell. The unusual wrinkle here is the direction of trust: the vulnerable party is the client side of the tunnel, exploited by a malicious server. That narrows the population that's realistically at risk to appliances configured to reach out to BOVPN-over-TLS endpoints, but for organizations running branch-to-hub topologies that's a common configuration, and root-level code execution on a perimeter device is as bad as it gets. Patch and confirm your tunnel endpoints.

Related stories