WatchGuard Fireware OS Critical Code Injection Vulnerability in BOVPN over TLS Client (CVE-2026-86131)
WatchGuard Fireware OS Critical Code Injection Vulnerability (TL-2026-2813) is a critical-severity software vulnerability scored CVSS 9.2, first published 2026-09-30. It has no confirmed attribution, affects WatchGuard Fireware OS (Firebox), references 10 CVEs (CVE-2026-86131, CVE-2026-86134, CVE-2026-86104), maps to 8 MITRE ATT&CK techniques (T1005, T1059, T1059.004), and is covered by 9 detection rules and 7 indicators of compromise.
Key facts for TL-2026-2813
- Threat ID
- TL-2026-2813
- Severity
- CRITICAL
- CVSS
- 9.2
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- 2026-09-30
- Last reviewed
- 2026-09-30
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, finance, health, manufacturing, education, small-business
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 7
WatchGuard patched a critical code injection flaw (CVE-2026-86131, CVSS 9.2) in how Fireware OS handles BOVPN over TLS client configurations, letting a remote attacker who controls a VPN server execute root-level commands on connecting Firebox appliances. The same update fixes 13 high-severity and 1 medium-severity vulnerabilities; WatchGuard reports no evidence of in-the-wild exploitation.
How WatchGuard Fireware OS Critical Code Injection Vulnerability works
WatchGuard advisory CVE-2026-86131, titled 'Code Injection in BOVPN Over TLS Client Allows Remote Code Execution', was published on 2026-09-29 by WatchGuard PSIRT with a CVSS score of 9.2 (Critical) and a weakness class of code injection (CWE-94). The flaw sits in the way Fireware OS processes configuration delivered to a BOVPN over TLS client. A remote attacker who controls the VPN server a Firebox connects to can inject commands that execute with root privileges on the appliance, without authenticating to the firewall itself.
Affected versions per the advisory: on the default platform set, Fireware OS >= 2026.3 and < 2026.3.2, >= 2025.0 and < 2026.2.3, and >= 12.0 and < 12.12.3; on T15/T35 models, >= 12.0 and < 12.5.21. Fixed releases are Fireware OS 2026.3.2, 2026.2.3, 12.12.3 and 12.5.21.
The same release train fixes 13 further high-severity flaws and 1 medium-severity flaw. Per SecurityWeek, the high-severity flaws cover remote code execution, authorization bypass, denial of service, unauthorized SSLVPN access and arbitrary local file reads, and several could be exploited by remote attackers without authentication; the medium flaw is improper authorization leading to unauthorized web application access. The WatchGuard PSIRT index for September 2026 lists: CVE-2026-86134 (pre-authentication NULL pointer dereference, remote DoS, CVSS 8.7, published 2026-09-30), CVE-2026-86104 (resource exhaustion in the login process, DoS, CVSS 8.7), CVE-2026-18145 (stack-based buffer overflow in spamd, RCE, CVSS 8.6), CVE-2026-81433 (pre-authentication stack buffer overflow in fingerd, RCE, CVSS 8.7), CVE-2026-13046 (deserialization of untrusted data in samld, RCE, CVSS 7.5) and CVE-2026-86101 (authorization bypass in SAML login allowing unauthorized SSLVPN access, CVSS 7.2). The full enumeration of the 13 high-severity flaws was not available in the sources; the per-advisory pages returned HTTP 403 to automated fetches.
WatchGuard also fixed two critical access point flaws in AP firmware 3.4.8 (advisories published 2026-09-28): CVE-2026-101891 (improper access control in the API service allowing unauthenticated access, CVSS 9.3) and CVE-2026-86102 (command injection in the internal management API, CVSS 9.3), which together permit unauthenticated API session acquisition and arbitrary shell command execution. A high-severity OS command injection requiring administrative privileges was fixed in the same AP release. Separately, CVE-2026-95676 (CVSS 7.4, published 2026-09-23) fixes a first-factor authentication bypass in the AuthPoint Gateway LDAP sync.
WatchGuard states it is not aware of in-the-wild exploitation of these issues. No public PoC, no network or file IOCs and no CVSS vector string were available in the sources reviewed. Firebox appliances are perimeter devices and WatchGuard VPN flaws have been targeted before (for example CVE-2025-9242, an IKEv2 out-of-bounds write with CVSS 4.0 9.3, disclosed October 2025), so prompt patching is recommended.
MITRE ATT&CK techniques used in TL-2026-2813
Collection
Execution
T1059 Command and Scripting Interpreter; T1059.004 Command and Scripting Interpreter: Unix Shell; T1203 Exploitation for Client Execution
Initial Access
T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application
Impact
T1499.004 Endpoint Denial of Service: Application or System Exploitation
Affected products and versions in WatchGuard Fireware OS Critical Code Injection Vulnerability
- WatchGuard — Fireware OS (Firebox)
Vulnerable versions: >= 2026.3, < 2026.3.2; >= 2025.0, < 2026.2.3; >= 12.0, < 12.12.3; T15/T35: >= 12.0, < 12.5.21
Fixed in: 2026.3.2; 2026.2.3; 12.12.3; 12.5.21 (T15/T35) - WatchGuard — WatchGuard Access Point firmware (CVE-2026-101891, CVE-2026-86102)
Vulnerable versions: < 3.4.8
Fixed in: 3.4.8
Remediation for WatchGuard Fireware OS Critical Code Injection Vulnerability
Patches
- Fireware OS 2026.3.2
- Fireware OS 2026.2.3
- Fireware OS 12.12.3
- Fireware OS 12.5.21 (T15/T35)
- WatchGuard AP firmware 3.4.8 (CVE-2026-101891, CVE-2026-86102)
Immediate actions
- Upgrade Firebox appliances to Fireware OS 2026.3.2, 2026.2.3, 12.12.3, or 12.5.21 (T15/T35) as applicable
- Inventory Firebox devices configured as BOVPN over TLS clients and identify the VPN servers they connect to
- Upgrade WatchGuard access points to AP firmware 3.4.8
Longer-term hardening
- Restrict BOVPN over TLS client connections to trusted, verified VPN servers only
- Restrict management and SSLVPN exposure on the Firebox to required source addresses
- Monitor WatchGuard PSIRT for new advisories and subscribe to security notifications
CVEs associated with WatchGuard Fireware OS Critical Code Injection Vulnerability
CVE-2026-86131, CVE-2026-86134, CVE-2026-86104, CVE-2026-18145, CVE-2026-81433, CVE-2026-13046, CVE-2026-86101, CVE-2026-101891, CVE-2026-86102, CVE-2026-95676
Weaknesses (CWE) in WatchGuard Fireware OS Critical Code Injection Vulnerability
CWE-94
Timeline of WatchGuard Fireware OS Critical Code Injection Vulnerability
- WatchGuard disclosed CVE-2025-9242, a critical IKEv2 VPN out-of-bounds write in Fireware OS (CVSS 4.0 9.3), the previous critical Firebox VPN flaw.
- WatchGuard released Fireware v2026.2 alongside 12.12 and 12.5.18, the release line later patched by 2026.2.3.
- Fireware v2026.3 released (initially for Firebox M4850, M5850 and M6850), functionally equivalent to v12.12/v2026.2; this line is later fixed by 2026.3.2.
- WatchGuard released Fireware OS 2026.2.2 and 12.12.2 with security fixes, preceding the current patch round.
- WatchGuard PSIRT published CVE-2026-95676 (CVSS 7.4), a first-factor authentication bypass in AuthPoint Gateway LDAP sync.
- WatchGuard PSIRT published critical access point advisories CVE-2026-101891 and CVE-2026-86102 (both CVSS 9.3), fixed in AP firmware 3.4.8.
- WatchGuard PSIRT published the advisory for CVE-2026-86131 (CVSS 9.2) with fixes in Fireware OS 2026.3.2, 2026.2.3, 12.12.3 and 12.5.21, alongside CVE-2026-18145, CVE-2026-81433, CVE-2026-13046, CVE-2026-86101 and CVE-2026-86104 and other high/medium fixes.
- SecurityWeek reported the patches and noted WatchGuard is not aware of in-the-wild exploitation; CVE-2026-86134 (pre-auth NULL pointer dereference DoS, CVSS 8.7) was published the same day.
Sources cited for WatchGuard Fireware OS Critical Code Injection Vulnerability
- WatchGuard Patches Critical Fireware OS Code Injection Vulnerability
- WatchGuard PSIRT
- WatchGuard PSIRT advisory CVE-2026-86131
- WatchGuard PSIRT advisory CVE-2026-18145 (spamd stack overflow)
- WatchGuard PSIRT advisory CVE-2026-101891 (AP API access control)
- NVD - CVE-2026-86131
- Fireware Release Notes v2026.3
- Fireware Release Notes v2026.2
- WatchGuard Fireware v2026.2, 12.12 and 12.5.18 now available
- Critical WatchGuard Fireware OS Flaw Enables Remote Code Execution (CVE-2025-9242, related prior VPN flaw)
More in vulnerability
- Cisco Catalyst SD-WAN Manager API authentication bypass zero-day (CVE-2026-76504) exploited in the wild
- GTIG: AI-Era Vulnerability Discovery and Exploitation Surge — In-the-Wild Exploitation of BeyondTrust CVE-2026-1731, LiteLLM CVE-2026-42271 and Langflow CVE-2026-5027
- CVE-2026-74864 / CVE-2026-74865: Authentication bypass in YunoHost-Apps sogo_yhn (SOGo proxy-auth trust)
- Docker CopyEscape (CVE-2026-17106): docker cp / sbx cp flaw lets malicious containers overwrite host files
- Critical MikroTik RouterOS Integer Underflow Vulnerability (CVE-2026-84411) Enables Unauthenticated Remote Code Execution
Detection coverage for TL-2026-2813
As of 2026-09-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2813 across Splunk SPL, Microsoft KQL and Sigma, covering 7 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.