SOCLYDE logo
Current languageEN
Cybersecurity newsFirewallsVulnerabilityNetworks

Watchguard fixes 15 fireware os flaws

One critical code-injection flaw and 14 other vulnerabilities affect Fireware OS. Check the fixed versions and affected scope.

By Soclyde Team

A technician prepares a network firewall during maintenance

In summary

  • WatchGuard and SecurityWeek report 15 patched vulnerabilities in Fireware OS.
  • CVE-2026-86131 can allow root-level command execution under a specific BOVPN TLS condition.
  • Install a fixed Fireware release for the relevant branch and appliance model.

Explore next

Soclyde resources

Article contents

WatchGuard has released fixes for 15 vulnerabilities in Fireware OS, the operating system used by Firebox firewalls. CVE-2026-86131 is a critical code-injection flaw tied to a specific BOVPN over TLS configuration. The vendor’s advisory and SecurityWeek describe a path that could lead to root-level command execution on the connecting appliance.

A flaw tied to a remote VPN server

CVE-2026-86131 concerns how Fireware handles BOVPN over TLS client configurations. The described scenario requires the attacker to control the remote VPN server to which the Firebox connects. That condition matters: the flaw does not mean any internet host can send a request and take over any firewall directly.

The flaw has a CVSS score of 9.2. The same patch set covers 13 high-severity vulnerabilities and one medium-severity issue with different mechanics, including code execution, authorization bypass, denial of service, unauthorized SSLVPN access and file reads depending on the defect.

Affected release branches

Fixed releases for the main branches are Fireware OS 2026.3.2, 2026.2.3 and 12.12.3. T15 and T35 models have a separate branch fixed in 12.5.21. Administrators should compare the installed release and model with the vendor’s affected-version table rather than use one generic version number.

CSIRT Toscana lists affected versions and recommends installing the updates associated with WatchGuard’s advisories. The critical fix is part of a wider security release; upgrading also closes other flaws from the same batch.

Upgrade and review connections

Inventory Firebox appliances, their Fireware branches and configured BOVPN over TLS tunnels. Plan an upgrade to the appropriate fixed release, then verify that tunnels and VPN rules return to expected operation.

For the critical issue, identify the remote VPN servers to which appliances connect and confirm they are controlled by the organization or trusted partners. A temporary connection restriction may reduce risk in some environments, but it does not replace WatchGuard’s software update.

What the exploitation notice says

SecurityWeek reports that WatchGuard was not aware of active exploitation when it announced the fixes. That statement reflects the information available at that time; it does not guarantee that exploitation will not be discovered later. Apply fixed releases through the normal change process and retain useful diagnostic records.

How Soclyde fits

Soclyde does not protect Firebox appliances or replace Fireware updates. A password vault can help teams manage unique VPN and administrator secrets, alongside patching and connection controls.

Key points

Fireware OS received fixes for 15 vulnerabilities, including a critical flaw that depends on a specific configuration and remote VPN server. Check the appliance’s release branch, install the fixed version and review BOVPN over TLS connections. For network-access secrets, see our guide to secure password sharing.

For handling shared access with clear sharing and revocation rules, see our guide to secure team password sharing.

To create unique secrets for network access, see our secure password generator guide.

To discuss managing the relevant access, you can also contact Soclyde.

Frequently asked questions

What is the critical Fireware OS flaw?

CVE-2026-86131 is a code-injection issue tied to a BOVPN over TLS client configuration. WatchGuard and SecurityWeek say an attacker must control the remote VPN server the Firebox connects to.

Which versions contain the fix?

The fixed releases listed are Fireware OS 2026.3.2, 2026.2.3, 12.12.3 and 12.5.21. The relevant branch depends on the appliance and model; check WatchGuard’s advisories before upgrading.

Is the flaw being exploited?

SecurityWeek reports that WatchGuard was not aware of active exploitation when it published the story. That status can change and does not remove the need to apply fixes.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading