WatchGuard released updates for Fireware OS addressing 15 vulnerabilities in Firebox appliances, led by CVE-2026-86131, a critical CVSS 9.2 code-injection flaw in BOVPN over TLS client configuration handling. An attacker that controls a remote VPN server can exploit the issue when a Firebox connects to it, executing arbitrary commands as root on the appliance. Fixed releases are Fireware OS 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21.
The update also fixes high-severity issues including CVE-2026-86132 and CVE-2026-86133, integer-underflow flaws in IKEv2 processing that can crash the iked process with crafted encrypted messages; CVE-2026-81433, an adjacent-network DHCP fingerprinting daemon buffer overflow; and CVE-2026-86101, which can grant some authenticated SAML users unauthorized Mobile VPN with SSL access. WatchGuard said it has no evidence of active exploitation, but organizations should urgently update affected Firebox devices, particularly deployments using BOVPN over TLS.

Map this exposure pattern across your cloud, code, and identities.
2 events from the most recent confirmed update back to the earliest known activity.
WatchGuard released security updates addressing 15 Fireware OS vulnerabilities affecting Firebox appliances, including critical CVE-2026-86131. The updates fixed the flaws in versions 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21; WatchGuard said it was unaware of in-the-wild exploitation.
WatchGuard patched two critical internal-API vulnerabilities that could let an unauthenticated attacker establish an API session and execute shell commands, plus a high-severity command-injection flaw. The fixes were released in WatchGuard AP version 3.4.8.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
3 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcecert.gov.py
Open sourcesecurityweek.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.