TL;DR
WatchGuard disclosed 14 Fireware OS vulnerabilities on September 29, 2026, affecting its Firebox firewalls. The worst, CVE-2026-86131, scores CVSS 9.2 and allows remote code execution in certain VPN setups. Fixed releases include Fireware OS 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21.
- Total: 14 CVEs
- Severity: 1 Critical · 12 High · 1 Medium
- Actively exploited: None confirmed
- Highest severity: 9.2 (Critical · CVSSv4) — CVE-2026-86131
- Action: Apply the latest security updates now
Tired of noisy CVE feeds? Set your own EPSS/CVSS alert threshold.
Try free for 14 daysNotable CVEs
| CVE | CVSS (CVSSv4) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-86131 | 9.2 | Code Injection in BOVPN Over TLS Client Allows Remote Code Execution | 2026.3.2, 2026.2.3, 12.12.3 (+1) | Not exploited |
| CVE-2026-81433 | 8.7 | Pre-Authentication Stack Buffer Overflow in fingerd Allows Remote Code Execution | 2026.3.2, 2026.2.3, 12.12.3 | Not exploited |
| CVE-2026-86104 | 8.7 | Resource Exhaustion in Login Process Allows Denial of Service | 2026.3.2, 2026.2.3, 12.12.3 (+1) | Not exploited |
| CVE-2026-18145 | 8.6 | Stack-based Buffer Overflow in spamd Allows Remote Code Execution | 2026.3.2, 2026.2.3, 12.12.3 (+1) | Not exploited |
| CVE-2026-13224 | 8.2 | Path Traversal in WebUI Management Agent Allows Arbitrary Local File Read | 12.5.21, 2026.3.2, 2026.2.3 (+1) | Not exploited |
| CVE-2026-86128 | 8.2 | NULL Pointer Dereference in NetFlow IPv6 Traffic Processing Allows Remote Denial of Service | 2026.3.2, 2026.2.3, 12.12.3 (+1) | Not exploited |
| CVE-2026-86132 | 8.2 | Pre-Authentication Integer Underflow in iked Allows Denial of Service | 2026.3.2, 2026.2.3, 12.12.3 (+1) | Not exploited |
| CVE-2026-86133 | 8.2 | Pre-Authentication Integer Underflow in iked Allows Remote Denial of Service | 2026.3.2, 2026.2.3, 12.12.3 (+1) | Not exploited |
Why These Fireware OS Vulnerabilities Matter
Firebox appliances guard the network edge and terminate VPN connections for many businesses. Edge devices are a favorite target, because a single foothold can open the whole network. This batch includes one Critical flaw, twelve High, and one Medium. Several can be triggered without logging in.
How the Attacks Work
BOVPN Over TLS Code Injection (CVE-2026-86131, CVSS 9.2)
The top flaw sits in the BOVPN Over TLS client. According to WatchGuard, it affects Firebox systems configured with a BOVPN Over TLS connection to an attacker-controlled destination. A malicious remote peer can inject code into the Firebox without authentication.
Pre-Authentication fingerd Overflow (CVE-2026-81433, CVSS 8.7)
A stack buffer overflow in the fingerd service can lead to remote code execution before login. The CVSS vector rates it as reachable from an adjacent network, not the open internet. Laurent Gaffie of secorizon.com reported it.
Denial of Service and Other Flaws
Several bugs let attackers crash or stall the device. They include a login resource exhaustion issue (CVE-2026-86104), two pre-auth IKEv2 integer underflows, and a NetFlow IPv6 crash. Other fixes cover a spamd buffer overflow, a SAML login authorization bypass for SSL VPN, and an admin-only path traversal.
Affected Versions and Exploitation Status
The flaws affect the Fireware OS 12.x, 2025.x, and 2026.x lines, with exact ranges varying by CVE. For every issue, WatchGuard states it “is not aware of any exploitation of this vulnerability in the wild.” No public proof-of-concept has been confirmed.
Patch and Mitigation Steps
Upgrade to Fireware OS 2026.3.2, 2026.2.3, 12.12.3, or 12.5.21, depending on your branch. EUCC-certified 12.11 builds should move to 12.11.10. Each issue has its own entry on the WatchGuard PSIRT portal. Until you patch, restrict the management Web UI and Access Portal to trusted networks. Also review BOVPN Over TLS and IKEv2 VPN peers, since those settings expose the most serious Fireware OS vulnerabilities.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!