Malicious VPN Server Could Seize Root Control of WatchGuard Firebox Appliances

WatchGuard patched 15 Fireware OS flaws, including critical CVE-2026-86131 for root RCE via malicious BOVPN over TLS server.

Malicious VPN Server Could Seize Root Control of WatchGuard Firebox Appliances
Vulnerabilities

Illustrative image generated with AI

Listen to this articleAudio edition · 9 min

Fireware update closes a root-level attack path

WatchGuard has released security updates for Fireware OS addressing 15 vulnerabilities, including a critical command-injection flaw that could give a remote attacker root-level control of a Firebox appliance.

The critical vulnerability, CVE-2026-86131, carries a CVSS score of 9.2. It affects Fireware OS configurations that use BOVPN over TLS in client mode.

According to SecurityAffairs’ September 30, 2026 report, exploitation does not require prior privileges or interaction from a user. However, the attacker must control the remote VPN server to which the vulnerable Firebox connects.

A successful attack would allow commands to run as root on the appliance. That level of access could place the firewall itself under the attacker’s control, rather than merely compromising a user account or an application behind it.

WatchGuard addressed the flaw in its September 29 security updates. The fixed Fireware OS releases are:

  • Fireware OS 2026.3.2
  • Fireware OS 2026.2.3
  • Fireware OS 12.12.3
  • Fireware OS 12.5.21

Affected branches include versions below those releases, although applicability varies by platform. The available reports do not provide a complete version-to-platform matrix, so administrators should compare each appliance against WatchGuard’s applicable fixed branch.

Why BOVPN over TLS creates an exposed trust boundary

CVE-2026-86131 lies in Fireware OS’s handling of BOVPN over TLS client configurations. BOVPN over TLS is a client-server mechanism used to establish VPN tunnels between Firebox appliances.

The feature can transport VPN traffic over TCP port 443, a port commonly permitted through network firewalls because it is also used for HTTPS. That makes the protocol practical in environments where other VPN transport methods may encounter restrictive filtering.

In the attack scenario described by the reports, the Firebox operates as the client and connects to a VPN server controlled by the attacker. Malicious input delivered through that connection can reach the vulnerable Fireware OS component and result in command execution with root privileges.

This condition differs from a broadly exposed, unauthenticated service that any internet host can attack directly. Control of the remote endpoint is a specific prerequisite. Nevertheless, organizations should treat configured VPN peers as part of the appliance’s security boundary, particularly when connections involve infrastructure managed by another organization or provider.

Root execution sharply raises the potential impact. Firewalls process sensitive network traffic and enforce access controls between security zones. A compromise at that layer could affect the integrity of the appliance and the protections that depend on it, although the cited reports do not describe any observed attacks or post-exploitation activity.

Fourteen additional Fireware flaws broaden the update’s scope

The Fireware OS release fixes more than the single critical issue. The full set consists of one critical vulnerability, 13 high-severity vulnerabilities and one medium-severity vulnerability.

Collectively, the high-severity defects can lead to outcomes including remote code execution, authorization bypass, denial of service, unauthorized SSLVPN access and arbitrary local file reads. Several may be remotely exploitable without authentication, according to SecurityWeek, although its report does not identify which individual flaws have that property.

Two of the high-severity vulnerabilities have additional technical detail.

CVE-2026-86101, rated CVSS 7.2, is an authorization flaw in the SAML login process. A remote user who has authenticated through SAML and can reach the Access Portal could submit a specially constructed request to obtain unauthorized Mobile VPN with SSL access.

This issue therefore has an authentication prerequisite, but successful exploitation could grant a VPN capability that the user was not authorized to receive. The same four Fireware OS releases that correct CVE-2026-86131 also address CVE-2026-86101.

CVE-2026-81433, rated CVSS 8.7, is a stack-based buffer overflow in fingerd, the DHCP fingerprinting daemon. An unauthenticated attacker with adjacent network access could send a crafted DHCP packet and potentially execute arbitrary code or crash the process.

The adjacent-network requirement narrows where the attack can originate, but the lack of authentication remains significant. DHCP traffic may also reach systems through network paths different from those used by ordinary routed application traffic.

The medium-severity issue is another authorization defect that could allow unauthorized access to web applications. The cited reports do not provide its CVE identifier or further technical details.

Firebox administrators should prioritize configured VPN clients

Administrators should first inventory Firebox appliances, record their Fireware OS branches and determine whether they fall below the relevant fixed release. Systems should then be upgraded to 2026.3.2, 2026.2.3, 12.12.3 or 12.5.21, depending on the platform and supported branch.

Appliances with BOVPN over TLS enabled in client mode warrant the highest priority because that configuration exposes the code path affected by CVE-2026-86131. Administrators should also review which remote VPN servers those appliances are configured to trust and whether each endpoint remains expected and controlled.

The update should not be limited to systems using BOVPN over TLS. The remaining fixes cover separate components and attack conditions, including SAML authorization, SSLVPN access and DHCP fingerprinting. An appliance not exposed to CVE-2026-86131 may still be vulnerable to other issues in the release.

WatchGuard was not aware of exploitation in the wild involving the Fireware OS vulnerabilities, according to the reports. SecurityWeek also relayed a broader WatchGuard statement that it was unaware of exploitation of any of the security issues discussed in connection with both Fireware OS and Access Point products.

That is a vendor assessment, not evidence that vulnerable systems can safely remain unpatched. No observed exploitation was described in either report.

Access Point patches accompanied the Fireware release

The Fireware OS fixes arrived one day after WatchGuard addressed three vulnerabilities in its Access Point software: two critical issues and one high-severity command-injection flaw.

The critical vulnerabilities, CVE-2026-101891 and CVE-2026-86102, affect internal API services. They could reportedly allow an unauthenticated attacker to obtain a valid API session and execute arbitrary shell commands on the underlying operating system.

The third Access Point vulnerability is a high-severity OS command-injection issue requiring administrative privileges. Its identifier was not included in the cited report.

WatchGuard fixed all three Access Point vulnerabilities in WatchGuard AP version 3.4.8. Organizations operating both Firebox appliances and WatchGuard access points should therefore treat the releases as two distinct upgrade tasks: update Fireware OS to the correct fixed branch and bring affected access points to version 3.4.8.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Back to home

Latest Cybersecurity News

All cybersecurity news →