WatchGuard Fireware OS (29–30 Sep): CVE-2026-86131 BOVPN-over-TLS code injection RCE (CVSS 9.2) + 14 other fixes; patch 2026.3.2 / 12.12.3
WatchGuard PSIRT (published 29–30 September 2026; SecurityWeek 30 Sep) released a Fireware OS security train fixing 15 issues. Critical: CVE-2026-86131 (CVSS v4 9.2) — code injection in BOVPN over TLS client configuration handling lets an attacker who controls the remote VPN server execute commands as root on the connecting Firebox. Fixed in Fireware OS 2026.3.2, 2026.2.3, 12.12.3 and 12.5.21 (T15/T35). The same trains also address high-severity pre-auth RCE/DoS (including fingerd stack overflow CVE-2026-81433, spamd overflow CVE-2026-18145, iked underflows, samld deserialization), SSLVPN SAML auth bypass CVE-2026-86101, WebUI path traversal CVE-2026-13224, wgagent DoS, and related. Distinct from desk watchguard-ap-api-20260928 (AP firmware) and the August iked/Dimension cluster (watchguard-fireware-iked-20260827). Vendor: not aware of in-the-wild exploitation of 86131. Primary: WatchGuard PSIRT / CVE.report; wire: SecurityWeek 30 Sep.
- Product
- WatchGuard Fireware OS (Firebox; BOVPN over TLS client and related services)
- Versions
- Affected (86131 Default platform): Fireware OS >=2026.3 <2026.3.2; >=2025.0 <2026.2.3; >=12.0 <12.12.3. T15/T35: >=12.0 <12.5.21. Fixed: 2026.3.2, 2026.2.3, 12.12.3, 12.5.21. Companion Sep 29–30 Fireware CVEs share these trains (see PSIRT catalog).
- CVSS
- (CVSS v4.0 CRITICAL, WatchGuard CNA — CVE-2026-86131); companion Highs include 8.7/8.6/8.2 per PSIRT list
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N (86131) - Exploited in Australia?
- unknown
- Patch to
- Upgrade Fireware OS to 2026.3.2 / 2026.2.3 / 12.12.3 / 12.5.21 (match your branch). Prioritise Fireboxes using BOVPN over TLS and internet-facing VPN/management services. Confirm version after reboot; WatchGuard reports no known exploitation of CVE-2026-86131.
Primary: WatchGuard PSIRT — CVE-2026-86131 Fireware BOVPN-over-TLS RCE (29 Sep 2026) · Vendor: WatchGuard — security advisories · CVE: CVE-2026-86131, CVE-2026-81433, CVE-2026-18145, CVE-2026-86101, CVE-2026-13224 · CVE.report — CVE-2026-86131 (CVSS v4 9.2 CRITICAL)
