WatchGuard Patches Critical Fireware OS Code Injection Flaw
WatchGuard released fixes for 15 Fireware OS vulnerabilities, including critical CVE-2026-86131 (CVSS 9.2), a code injection flaw in BOVPN over TLS that lets a remote attacker run commands as root on a connecting Firebox. Patches shipped in versions 2026.3.2, 2026.2.3, 12.12.3 and 12.5.21.
- CVE-2026-86131 rated CVSS 9.2 is a code injection in BOVPN over TLS
- Exploitation grants root access on the connecting Firebox
- Fixed in Fireware OS 2026.3.2, 2026.2.3, 12.12.3 and 12.5.21
- 13 high-severity and one medium-severity flaws also patched
Read next
Security