Breaking
SecurityDeveloping Story

WatchGuard Patches 15 Fireware OS Flaws

WatchGuard fixed a critical Fireware OS code injection flaw and 13 high-severity bugs, plus three Access Point vulnerabilities disclosed a day earlier.

··3 hours ago·4 min read
a bunch of wires that are connected to a server
Photo by Lightsaber Collection on Unsplash

WatchGuard has released updates for its Fireware OS after disclosing 15 vulnerabilities, including a critical-severity remote code execution bug that could give an attacker root-level control of a connecting Firebox appliance. The fixes arrived alongside separate patches for the company's Access Point product line, disclosed one day earlier, giving administrators two distinct sets of updates to apply.

According to the company, it is not aware of any of these security issues being exploited in the wild. The advisories list the affected versions and the fixed releases, with additional information available on the company's security advisories page.

Inside the Critical Fireware Bug

The most severe issue is tracked as CVE-2026-86131 and carries a CVSS score of 9.2. It is described as a code injection problem in how Fireware OS handles BOVPN over TLS client configurations.

Successful exploitation could allow a remote attacker who controls the remote VPN server to run commands with root privileges on the connecting Firebox appliance. That means the attacker would need to be on the other end of the VPN connection — not just any internet-facing host.

WatchGuard resolved the weakness in Fireware OS versions 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21. Administrators running earlier builds remain exposed until they upgrade to one of those releases.

High-Severity Bugs and What They Do

The Fireware OS update also addresses 13 high-severity vulnerabilities. According to the source, these could lead to remote code execution, authorization bypass, denial-of-service, unauthorized SSLVPN access, and arbitrary local file reads.

One additional medium-severity flaw — an improper authorization issue — was patched as well. That bug could have allowed unauthorized access to web applications.

Several of the security defects could be exploited by remote attackers without authentication, which broadens the pool of potential attackers beyond those with existing credentials.

Access Point Patches a Day Earlier

The Fireware OS patches landed one day after WatchGuard rolled out fixes for two critical and one high-severity Access Point flaw.

Those issues are tracked as CVE-2026-101891 and CVE-2026-86102 and affect internal API services. The critical bugs could be exploited to obtain a valid API session without authentication and to execute arbitrary shell commands on the underlying operating system.

The high-severity weakness is an OS command injection that requires administrative privileges to exploit. All three vulnerabilities were resolved in WatchGuard AP version 3.4.8.

No Known Exploitation, but Updates Pending

WatchGuard stated it is not aware of any of these security issues being exploited in the wild. The company published the affected versions and fixed releases, and pointed to its security advisories page for further detail.

Across the two advisories, the affected products break down as follows:

  • 15 vulnerabilities in Fireware OS, including one critical (CVSS 9.2)
  • 13 high-severity Fireware OS flaws enabling RCE, authorization bypass, DoS, unauthorized SSLVPN access, and arbitrary local file reads
  • 1 medium-severity improper authorization issue in Fireware OS
  • 2 critical and 1 high-severity Access Point flaws affecting internal API services
  • Fixed Fireware OS releases: 2026.3.2, 2026.2.3, 12.12.3, 12.5.21
  • Fixed Access Point release: 3.4.8

The source did not include a direct quotation from a named WatchGuard spokesperson or researcher, so no blockquote is provided here.

What Administrators Should Do Now

For anyone running Fireware OS, the practical step is to confirm the current build and upgrade to one of the fixed versions: 2026.3.2, 2026.2.3, 12.12.3, or 12.5.21. Because the critical code injection flaw is tied to BOVPN over TLS client configuration, environments that use that feature should treat the update as a priority.

Access Point administrators should separately verify they are on AP version 3.4.8. The two advisories cover different product lines, so patching one does not address the other.

WatchGuard has not indicated any workaround short of applying the updates. The company's advisories page remains the authoritative source for affected versions and fixed releases.

Reading the Two Advisories Together

WatchGuard's disclosure did not name individual researchers or provide a timeline for when the bugs were reported. The advisories simply list the affected versions and the fixed releases, leaving administrators to map those against their own deployments.

The Fireware OS set is the larger of the two, with 15 vulnerabilities spanning a critical RCE, 13 high-severity issues, and one medium-severity authorization flaw. The Access Point set is smaller — two critical and one high-severity — but includes bugs that can be reached without authentication.

Both sets were published within a day of each other. The Fireware OS patches landed one day after the Access Point fixes, according to the source.

Why It Matters

For organizations running WatchGuard gear, the immediate takeaway is that two separate update cycles are now in play — one for Fireware OS and one for Access Point devices. Because the critical Fireware OS flaw requires an attacker to control the remote VPN server, exploitation would likely involve either compromising a legitimate peer or standing up a malicious endpoint that a Firebox is configured to connect to. That raises the bar compared with a flaw reachable by any unauthenticated internet user, but it does not remove the risk.

The Access Point bugs are a separate concern: two of them are critical and one requires no authentication, so unpatched access points could become an entry point into the networks they serve. The absence of known exploitation is a reason to move quickly, not to wait. Once patches are public, attackers sometimes reverse-engineer them to build exploits, and the critical BOVPN issue could become a target for anyone who can position a malicious VPN server in front of a Firebox. Administrators should treat both updates as time-sensitive rather than routine.

#watchguard#fireware os#vulnerability#patching#remote code execution#vpn

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories