WatchGuard has released Fireware OS updates addressing fifteen vulnerabilities, including a critical code-injection issue in BOVPN over TLS client handling. The flaw, CVE-2026-86131, could allow an attacker controlling the remote VPN server to execute commands with root privileges on a connecting Firebox appliance.
The update covers multiple remote attack paths
WatchGuard fixed the critical issue in Fireware OS 2026.3.2, 2026.2.3, 12.12.3 and 12.5.21. The same release set addresses high-severity vulnerabilities involving code execution, authorization bypass, denial of service, unauthorized SSLVPN access and local file reads. Separate access-point updates also resolve critical internal-API weaknesses that could provide an unauthenticated session or command execution.
Appliances should be upgraded as controlled security infrastructure
Operators should identify affected Firebox and access-point versions, back up configuration, verify supported upgrade paths and test VPN, routing, authentication and logging after deployment. Management interfaces should remain restricted while updates are staged. WatchGuard says it is not aware of exploitation in the wild, but internet-facing security appliances remain attractive targets and should not wait for confirmed attacks. SectechMedia’s guide to network redundancy and failover explains how to maintain service while critical infrastructure is upgraded.

Leave a Reply