WatchGuard Patches 15 Fireware OS Flaws
WatchGuard fixed a critical Fireware OS code injection flaw and 13 high-severity bugs, plus three Access Point vulnerabilities disclosed a day earlier.
WatchGuard has released updates for its Fireware OS after disclosing 15 vulnerabilities, including a critical-severity remote code execution bug that could give an attacker root-level control of a connecting Firebox appliance. The fixes arrived alongside separate patches for the company's Access Point product line, disclosed one day earlier, giving administrators two distinct sets of updates to apply.
According to the company, it is not aware of any of these security issues being exploited in the wild. The advisories list the affected versions and the fixed releases, with additional information available on the company's security advisories page.
Inside the Critical Fireware Bug
The most severe issue is tracked as CVE-2026-86131 and carries a CVSS score of 9.2. It is described as a code injection problem in how Fireware OS handles BOVPN over TLS client configurations.
Successful exploitation could allow a remote attacker who controls the remote VPN server to run commands with root privileges on the connecting Firebox appliance. That means the attacker would need to be on the other end of the VPN connection — not just any internet-facing host.
WatchGuard resolved the weakness in Fireware OS versions 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21. Administrators running earlier builds remain exposed until they upgrade to one of those releases.
High-Severity Bugs and What They Do
The Fireware OS update also addresses 13 high-severity vulnerabilities. According to the source, these could lead to remote code execution, authorization bypass, denial-of-service, unauthorized SSLVPN access, and arbitrary local file reads.
One additional medium-severity flaw — an improper authorization issue — was patched as well. That bug could have allowed unauthorized access to web applications.
Several of the security defects could be exploited by remote attackers without authentication, which broadens the pool of potential attackers beyond those with existing credentials.
Access Point Patches a Day Earlier
The Fireware OS patches landed one day after WatchGuard rolled out fixes for two critical and one high-severity Access Point flaw.
Those issues are tracked as CVE-2026-101891 and CVE-2026-86102 and affect internal API services. The critical bugs could be exploited to obtain a valid API session without authentication and to execute arbitrary shell commands on the underlying operating system.
The high-severity weakness is an OS command injection that requires administrative privileges to exploit. All three vulnerabilities were resolved in WatchGuard AP version 3.4.8.
No Known Exploitation, but Updates Pending
WatchGuard stated it is not aware of any of these security issues being exploited in the wild. The company published the affected versions and fixed releases, and pointed to its security advisories page for further detail.
Across the two advisories, the affected products break down as follows:
- 15 vulnerabilities in Fireware OS, including one critical (CVSS 9.2)
- 13 high-severity Fireware OS flaws enabling RCE, authorization bypass, DoS, unauthorized SSLVPN access, and arbitrary local file reads
- 1 medium-severity improper authorization issue in Fireware OS
- 2 critical and 1 high-severity Access Point flaws affecting internal API services
- Fixed Fireware OS releases: 2026.3.2, 2026.2.3, 12.12.3, 12.5.21
- Fixed Access Point release: 3.4.8
The source did not include a direct quotation from a named WatchGuard spokesperson or researcher, so no blockquote is provided here.
What Administrators Should Do Now
For anyone running Fireware OS, the practical step is to confirm the current build and upgrade to one of the fixed versions: 2026.3.2, 2026.2.3, 12.12.3, or 12.5.21. Because the critical code injection flaw is tied to BOVPN over TLS client configuration, environments that use that feature should treat the update as a priority.
Access Point administrators should separately verify they are on AP version 3.4.8. The two advisories cover different product lines, so patching one does not address the other.
WatchGuard has not indicated any workaround short of applying the updates. The company's advisories page remains the authoritative source for affected versions and fixed releases.
Reading the Two Advisories Together
WatchGuard's disclosure did not name individual researchers or provide a timeline for when the bugs were reported. The advisories simply list the affected versions and the fixed releases, leaving administrators to map those against their own deployments.
The Fireware OS set is the larger of the two, with 15 vulnerabilities spanning a critical RCE, 13 high-severity issues, and one medium-severity authorization flaw. The Access Point set is smaller — two critical and one high-severity — but includes bugs that can be reached without authentication.
Both sets were published within a day of each other. The Fireware OS patches landed one day after the Access Point fixes, according to the source.
Why It Matters
For organizations running WatchGuard gear, the immediate takeaway is that two separate update cycles are now in play — one for Fireware OS and one for Access Point devices. Because the critical Fireware OS flaw requires an attacker to control the remote VPN server, exploitation would likely involve either compromising a legitimate peer or standing up a malicious endpoint that a Firebox is configured to connect to. That raises the bar compared with a flaw reachable by any unauthenticated internet user, but it does not remove the risk.
The Access Point bugs are a separate concern: two of them are critical and one requires no authentication, so unpatched access points could become an entry point into the networks they serve. The absence of known exploitation is a reason to move quickly, not to wait. Once patches are public, attackers sometimes reverse-engineer them to build exploits, and the critical BOVPN issue could become a target for anyone who can position a malicious VPN server in front of a Firebox. Administrators should treat both updates as time-sensitive rather than routine.
Sources
- SecurityWeek Original source
- security advisories Also reporting
Continue Reading
Cloudflare Vows Quantum-Proof TLS Shift
Cloudflare says it will issue post-quantum TLS certificates using Merkle Tree Certificates, targeting Q1 2027 after acquiring a GlobalSign root.
AI-Discovered Flaws Skew Toward RCE
Google's threat intelligence unit reports AI-found vulnerabilities are far more likely to enable remote code execution than other disclosed flaws.
Teen's Auth Flaw Opened Titan's Data Vault
A 16-year-old researcher bypassed Microsoft's Titan analytics by exploiting an unverified JWT and was paid a $5,000 bounty.