WatchGuard has released fixes for 15 vulnerabilities in Fireware OS, the operating system used by Firebox firewalls. CVE-2026-86131 is a critical code-injection flaw tied to a specific BOVPN over TLS configuration. The vendor’s advisory and SecurityWeek describe a path that could lead to root-level command execution on the connecting appliance.
A flaw tied to a remote VPN server
CVE-2026-86131 concerns how Fireware handles BOVPN over TLS client configurations. The described scenario requires the attacker to control the remote VPN server to which the Firebox connects. That condition matters: the flaw does not mean any internet host can send a request and take over any firewall directly.
The flaw has a CVSS score of 9.2. The same patch set covers 13 high-severity vulnerabilities and one medium-severity issue with different mechanics, including code execution, authorization bypass, denial of service, unauthorized SSLVPN access and file reads depending on the defect.
Affected release branches
Fixed releases for the main branches are Fireware OS 2026.3.2, 2026.2.3 and 12.12.3. T15 and T35 models have a separate branch fixed in 12.5.21. Administrators should compare the installed release and model with the vendor’s affected-version table rather than use one generic version number.
CSIRT Toscana lists affected versions and recommends installing the updates associated with WatchGuard’s advisories. The critical fix is part of a wider security release; upgrading also closes other flaws from the same batch.
Upgrade and review connections
Inventory Firebox appliances, their Fireware branches and configured BOVPN over TLS tunnels. Plan an upgrade to the appropriate fixed release, then verify that tunnels and VPN rules return to expected operation.
For the critical issue, identify the remote VPN servers to which appliances connect and confirm they are controlled by the organization or trusted partners. A temporary connection restriction may reduce risk in some environments, but it does not replace WatchGuard’s software update.
What the exploitation notice says
SecurityWeek reports that WatchGuard was not aware of active exploitation when it announced the fixes. That statement reflects the information available at that time; it does not guarantee that exploitation will not be discovered later. Apply fixed releases through the normal change process and retain useful diagnostic records.
How Soclyde fits
Soclyde does not protect Firebox appliances or replace Fireware updates. A password vault can help teams manage unique VPN and administrator secrets, alongside patching and connection controls.
Key points
Fireware OS received fixes for 15 vulnerabilities, including a critical flaw that depends on a specific configuration and remote VPN server. Check the appliance’s release branch, install the fixed version and review BOVPN over TLS connections. For network-access secrets, see our guide to secure password sharing.
For handling shared access with clear sharing and revocation rules, see our guide to secure team password sharing.
To create unique secrets for network access, see our secure password generator guide.
To discuss managing the relevant access, you can also contact Soclyde.



