threat_intelligence306 wordsRead on Huntaegis

WatchGuard Patches Critical Fireware OS Vulnerability That Could Allow Command Execution with Root Privileges

542/69 Friday, October 2, 2026 WatchGuard has released security updates for Fireware OS to address a total of 15 vulnerabilities. The most significant issue is CVE-2026-86131, which has a CVSS score of 9.2 and is a code injection vulnerability in the configuration handling of the BOVPN over TLS Client. The flaw could allow an attacker who controls the remote VPN server to execute arbitrary commands with root privileges on a connected WatchGuard Firebox device. Exploitation does not require user interaction or prior privileges on the target device. CVE-2026-86131 affects the BOVPN over TLS functionality in Fireware OS, a feature used to establish VPN tunnels between WatchGuard Firebox devices through a client-server architecture. It can route VPN traffic over TCP port 443, which is commonly permitted through firewalls in many environments. If an attacker gains control of the VPN server to which a vulnerable Firebox connects, the flaw could be exploited to execute commands on the affected device with the highest level of privileges. WatchGuard has fixed the vulnerability in Fireware OS versions 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21. In addition to the Critical vulnerability, WatchGuard also fixed 13 High-severity vulnerabilities across several Fireware OS components. These flaws could lead to code execution, authorization bypass, denial of service, unauthorized SSLVPN access, and unauthorized file access. Examples include CVE-2026-86101, an improper authorization vulnerability in the SAML login process that could allow an authenticated SAML user with access only to the Access Portal to gain unauthorized access to Mobile VPN with SSL, and CVE-2026-81433, a stack-based buffer overflow in the fingerd process that could be triggered through a specially crafted DHCP packet. WatchGuard stated that it has not observed exploitation of these vulnerabilities in real-world attacks and recommends that organizations using Firebox devices review their Fireware OS versions and apply updates promptly, particularly on systems with BOVPN over TLS enabled.

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.