WatchGuard has released updates addressing multiple vulnerabilities in its Fireware OS, including a critical remote code execution (RCE) flaw. The vulnerability, identified as CVE-2026-86131 with a CVSS score of 9.2, involves a code injection problem connected to BOVPN over TLS client configurations.
Details of the Critical Vulnerability
The identified code injection vulnerability poses serious risks, as a remote attacker controlling the VPN server could potentially execute commands with root access on a Firebox appliance. This significant security issue has been rectified in Fireware OS versions 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21.
Aside from the critical flaw, the update also addresses 13 high-severity vulnerabilities. These include risks of remote code execution, authorization bypass, denial-of-service (DoS), unauthorized SSLVPN access, and arbitrary local file reads, all of which could be exploited by unauthenticated remote attackers.
Additional Security Enhancements
WatchGuard’s recent update also tackles a medium-severity issue related to improper authorization, which could lead to unauthorized access to web applications. These vulnerabilities underscore the importance of maintaining updated security protocols to prevent potential exploitation.
The comprehensive update follows closely on the heels of fixes for critical vulnerabilities in WatchGuard’s Access Point systems. These earlier patches addressed flaws identified as CVE-2026-101891 and CVE-2026-86102, which affected internal API services and allowed unauthorized shell command execution.
Future Outlook and Recommendations
While there have been no reports of these vulnerabilities being exploited in the wild, WatchGuard advises users to promptly update to the latest versions to safeguard their systems. For more detailed information, users are encouraged to visit WatchGuard’s security advisories page.
Staying informed and proactive in applying security updates is crucial for organizations to protect against potential cyber threats. The importance of cybersecurity cannot be overstated, as evidenced by recent vulnerabilities in major platforms like Chrome, Firefox, and Salesforce, which have also undergone patches for numerous flaws.
