WatchGuard Fixes Critical Fireware OS Code Injection Vulnerability

Network security management servers protected by restricted administrative access

Written by

in

WatchGuard has released Fireware OS updates addressing fifteen vulnerabilities, including a critical code-injection issue in BOVPN over TLS client handling. The flaw, CVE-2026-86131, could allow an attacker controlling the remote VPN server to execute commands with root privileges on a connecting Firebox appliance.

The update covers multiple remote attack paths

WatchGuard fixed the critical issue in Fireware OS 2026.3.2, 2026.2.3, 12.12.3 and 12.5.21. The same release set addresses high-severity vulnerabilities involving code execution, authorization bypass, denial of service, unauthorized SSLVPN access and local file reads. Separate access-point updates also resolve critical internal-API weaknesses that could provide an unauthenticated session or command execution.

Appliances should be upgraded as controlled security infrastructure

Operators should identify affected Firebox and access-point versions, back up configuration, verify supported upgrade paths and test VPN, routing, authentication and logging after deployment. Management interfaces should remain restricted while updates are staged. WatchGuard says it is not aware of exploitation in the wild, but internet-facing security appliances remain attractive targets and should not wait for confirmed attacks. SectechMedia’s guide to network redundancy and failover explains how to maintain service while critical infrastructure is upgraded.

Sources

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *