WatchGuard patches critical Fireware OS code injection flaw
WatchGuard has released security updates for Fireware OS, the operating system that runs on its Firebox firewall appliances. The updates fix 15 vulnerabilities, one of which is rated critical and can lead to remote code execution with root privileges.
The Fireware OS release came one day after the company patched three flaws in its Access Point products. Two of those were also rated critical.
WatchGuard says it is not aware of any of these vulnerabilities being exploited in the wild.
A malicious VPN server can take over the Firebox
The most serious issue is tracked as CVE-2026-86131 and has a CVSS score of 9.2. WatchGuard describes it as a code injection flaw in the way Fireware OS handles BOVPN over TLS client configurations. BOVPN stands for Branch Office VPN, WatchGuard's feature for connecting networks at different sites.
