WatchGuard patches critical Fireware OS code injection flaw
WatchGuard has released security updates for Fireware OS, the operating system that runs on its Firebox firewall appliances. The updates fix 15 vulnerabilities, one of which is rated critical and can lead to remote code execution with root privileges.
The Fireware OS release came one day after the company patched three flaws in its Access Point products. Two of those were also rated critical.
WatchGuard says it is not aware of any of these vulnerabilities being exploited in the wild.
A malicious VPN server can take over the Firebox
The most serious issue is tracked as CVE-2026-86131 and has a CVSS score of 9.2. WatchGuard describes it as a code injection flaw in the way Fireware OS handles BOVPN over TLS client configurations. BOVPN stands for Branch Office VPN, WatchGuard's feature for connecting networks at different sites.
The attack scenario is unusual. The attacker has to control the remote VPN server that a Firebox connects to. If the attack works, the attacker can run commands as root on the connecting Firebox appliance.
This turns the normal trust relationship around. Administrators usually treat the firewall as the protected side of a VPN link. Here, a hostile or compromised endpoint on the other side of the tunnel could gain full control of the device.
The flaw has been fixed in Fireware OS versions:
- 2026.3.2
- 2026.2.3
- 12.12.3
- 12.5.21
Thirteen high-severity bugs in the same release
The same updates address 13 high-severity vulnerabilities. Depending on the bug, successful exploitation could lead to:
- remote code execution
- authorization bypass
- denial-of-service (DoS)
- unauthorized SSLVPN access
- arbitrary reads of local files
WatchGuard also fixed one medium-severity improper authorization issue that could give attackers unauthorized access to web applications.
According to the company, several of the patched flaws can be exploited remotely and without authentication. For devices that sit at the network perimeter, this is the kind of detail that should move patching up the priority list.
Access Point flaws fixed a day earlier
The Fireware OS patches followed a separate set of fixes for WatchGuard's Access Point products.
Two critical bugs, tracked as CVE-2026-101891 and CVE-2026-86102, affect internal API services. By exploiting them, an attacker could get a valid API session without authenticating and then run arbitrary shell commands on the underlying operating system.
The third bug is a high-severity OS command injection issue. Unlike the critical flaws, exploiting it requires administrative privileges.
All three Access Point vulnerabilities are fixed in WatchGuard AP version 3.4.8. More details are available on WatchGuard's security advisories page.
Our Take
No exploitation has been reported so far, but the history of edge devices suggests the window for safe patching may be short. In recent weeks, the Check Point VPN RCE flaw and Citrix NetScaler bugs have both been attacked after disclosure. Firewalls and VPN gateways are attractive targets because they are exposed to the internet and give attackers a foothold inside the network.
The critical Fireware bug has a narrower attack path because it depends on a malicious VPN server. The unauthenticated high-severity flaws may be the bigger practical risk, especially the ones affecting SSLVPN access. Organizations running Firebox appliances or WatchGuard access points should update, and review which remote VPN endpoints their devices trust.
It is worth watching whether researchers publish technical details or proof-of-concept code in the coming days. With other vendors, that has often been the point where scanning and exploitation began.
