WatchGuard patches critical Fireware OS RCE (CVE-2026-86131)
WatchGuard fixed CVE-2026-86131 (CVSS 9.2), a code-injection flaw letting a malicious BOVPN-over-TLS server run root commands on a connecting Firebox, plus 13 more high-severity Fireware OS bugs.
WatchGuard has patched CVE-2026-86131, a CVSS 9.2 code-injection flaw in Fireware OS that lets an attacker who controls a BOVPN-over-TLS server execute commands with root privileges on the Firebox appliance that connects to it. It's the headline of a batch that fixes more than a dozen Fireware OS vulnerabilities.
The primary reference is WatchGuard's PSIRT advisory portal; the flaw is tracked at CVE-2026-86131.
What's affected
The bug is in how Fireware OS handles Branch Office VPN (BOVPN) over TLS client configurations. Exploitation requires the Firebox to connect, as a client, to a VPN server the attacker controls — so the practical prerequisite is control (or spoofing) of the remote BOVPN-over-TLS peer, not an unauthenticated hit against the box's public interface. Where that condition is met, the payload runs as root.
Fixed builds:
- Fireware OS 2026.3.2
- Fireware OS 2026.2.3
- Fireware OS 12.12.3
- Fireware OS 12.5.21
WatchGuard's release resolves 13 additional high-severity issues — further RCE, authorization bypass, denial of service, unauthorized SSLVPN access, and arbitrary local file read — plus one medium-severity improper-authorization flaw.
Exploitation status
None reported. WatchGuard states it is "not aware of any of these security issues being exploited in the wild." No public PoC has surfaced.
Action checklist
- Upgrade Fireware OS to 2026.3.2, 2026.2.3, 12.12.3, or 12.5.21 depending on your branch. Firebox appliances are perimeter devices — treat this as a same-cycle patch.
- Prioritize appliances that initiate BOVPN-over-TLS tunnels, especially hub-and-spoke deployments where a branch Firebox dials into a central endpoint.
- Validate the identity of BOVPN-over-TLS peers. Since exploitation hinges on the appliance connecting to a hostile server, confirm tunnel endpoints and certificates are what you expect.
- Review SSLVPN exposure given the additional high-severity SSLVPN and file-read fixes in the same release.
Context
Firewall and VPN appliances remain among the most heavily targeted classes of edge device, and Fireboxes are no exception — network gear that terminates VPN tunnels sits exactly where attackers want a root shell. The unusual wrinkle here is the direction of trust: the vulnerable party is the client side of the tunnel, exploited by a malicious server. That narrows the population that's realistically at risk to appliances configured to reach out to BOVPN-over-TLS endpoints, but for organizations running branch-to-hub topologies that's a common configuration, and root-level code execution on a perimeter device is as bad as it gets. Patch and confirm your tunnel endpoints.