WatchGuard Firebox flaw lets a rogue VPN server run root
CVE-2026-86131 (CVSS 9.2) lets a VPN server run root commands on a Firebox that connects to it over BOVPN over TLS. Fixed versions, checks and the other 14 fixes.
By Yaali. October 1, 2026, 6 min read, Vulnerabilities, Patching.
WatchGuard published fixes on September 29 for CVE-2026-86131, a code injection flaw in Fireware OS, the operating system of its Firebox firewalls. It is rated 9.2 (critical) under CVSS 4.0. A Firebox that connects out as the client end of a BOVPN over TLS tunnel can be made to run commands as root by whoever controls the VPN server at the other end. WatchGuard says it is not aware of any exploitation in the wild, and no public exploit has been reported.
The same release fixes 14 more Fireware flaws, among them a pre-authentication buffer overflow in a DHCP daemon and two IKEv2 crash bugs. If you run Fireboxes, you need one of four releases: 2026.3.2, 2026.2.3, 12.12.3, or 12.5.21 for the T15 and T35. The critical bug only matters to Fireboxes set up as BOVPN over TLS clients, but the rest of the batch reaches far more boxes, so plan the upgrade for every Firebox.

How it works
BOVPN (Branch Office VPN) over TLS has been in Fireware since version 12.1. It builds a site-to-site tunnel between two Fireboxes over TLS on TCP port 443, for networks that cannot pass IPsec traffic, since port 443 is open almost everywhere. It uses a client and server model: one Firebox runs in Server mode and accepts tunnels, the others run in Client mode and dial out to it by IP address or domain name, authenticating with a shared tunnel ID and a pre-shared key of 8 to 23 characters. A Firebox can be a client or a server, never both.
The bug sits on the client side, in how Fireware handles BOVPN over TLS client configuration. WatchGuard's description is that an attacker "who controls the remote VPN server" can inject code that the client Firebox then runs as root. The CVSS vector says no privileges and no user action are needed, but marks an attack requirement: the victim has to be configured to connect to a server the attacker controls. WatchGuard has not published the vulnerable field or parameter.
The advisory lists three weakness types: CWE-94 (code injection), CWE-829 (pulling in functionality from an untrusted source) and CWE-295 (improper certificate validation). The certificate entry suggests the client may not properly check that it is talking to the genuine server, which would widen the attack from "an attacker owns the server" to "an attacker can sit in the path or take over the server's name". WatchGuard has not said this explicitly, so treat it as a possibility rather than a confirmed route.
With root, the attacker controls the device that enforces your perimeter policy, terminates your VPNs and sees the traffic between your sites.
What attackers are doing
Nothing confirmed. WatchGuard states it is not aware of exploitation of this flaw or any of the others in the batch, and none of the sources we checked report a proof of concept.
The precondition limits who can use it. The realistic paths are a server-mode Firebox that is already compromised (so one breached hub could reach every client branch connected to it), a partner or supplier who runs the server end, or someone who can redirect the server's domain name. That last one depends on the certificate validation question above. Patches can be compared against the old code to work out the bug, so the absence of reports today is not a reason to wait.
The rest of the batch
SecurityWeek counts 13 high-severity flaws and one medium-severity flaw alongside the critical one; SecurityOnline's headline gives a total of 14 rather than 15. The ones to know:
- CVE-2026-81433 (CVSS 8.7): a stack buffer overflow in fingerd, the DHCP fingerprinting daemon. An unauthenticated attacker on an adjacent network can send a crafted DHCP packet to run code or crash the process. Adjacent means on a network segment the Firebox serves, such as a LAN or guest network.
- CVE-2026-86132 and CVE-2026-86133 (CVSS 8.2 each): integer underflows in iked, the IKEv2 daemon behind IPsec VPNs. The first lets an unauthenticated remote attacker crash iked with a crafted encrypted message when an AES-GCM cipher suite is negotiated; the second needs the initial IKEv2 handshake to be completed first. WatchGuard rates both as denial of service, so the risk is an outage of IPsec VPN service.
- CVE-2026-86101 (CVSS 7.2): a SAML login flaw that lets a user who is only allowed into the Access Portal get Mobile VPN with SSL access as well.
WatchGuard also fixed two critical flaws in its access point firmware, CVE-2026-101891 and CVE-2026-86102, in AP version 3.4.8. If you run WatchGuard APs, schedule that update alongside the Fireboxes.
What to do
- Upgrade every Firebox. Fixed releases: Fireware 2026.3.2 (for 2026.3), 2026.2.3 (for 2025.0 to 2026.2), 12.12.3 (for the 12.x branch) and 12.5.21 for T15 and T35, which stay on 12.5. In Fireware Web UI the upgrade is under System > Upgrade OS; cloud-managed Fireboxes are upgraded from WatchGuard Cloud. Do the BOVPN over TLS clients first, then everything else.
- Find your exposure. On each Firebox, open VPN > BOVPN over TLS. If it is enabled and the Firebox Mode is Client, note every Primary Server and Backup Server address. Each one should be a Firebox you operate or one run by a partner you can name.
- If you cannot upgrade today. WatchGuard lists no workaround. Our suggestion: disable client-mode tunnels to any server you do not fully control, and move tunnels that must stay up to IPsec BOVPN where the network allows it. Patch the server-side Firebox as well, since in our view a compromised hub is the likeliest route to its clients. For the fingerd and IKEv2 bugs there is no workaround in the sources either, so upgrading is the only fix.
- Check for signs of compromise. WatchGuard has published no indicators. Look in Traffic Monitor or your log server for BOVPN over TLS tunnels to addresses you do not recognise, for server domain names that resolve to an unexpected IP, and for configuration changes, new admin accounts or management logins you cannot explain. A Firebox that ran attacker commands as root cannot be trusted to report on itself, so compare against logs sent off the box.
- Clean up if anything looks wrong. Reinstall a fixed release, restore a configuration you know is clean, then rotate the BOVPN pre-shared keys, IPsec keys, admin passwords and any LDAP, RADIUS or SAML credentials stored on the Firebox.

Your VPN peers are an attack surface
Site-to-site tunnels tend to be configured once and forgotten, and a client device usually trusts whatever its peer sends. This bug shows why that trust should be written down: keep a list of every tunnel, who runs each end, and which ones reach third parties. When a partner's VPN endpoint can push data into your firewall, its security posture becomes part of yours.
If you want an outside view of your firewalls and VPN tunnels, our network penetration testing team tests them as an attacker would, and our safeguarding and hardening work tightens the configuration afterwards. Open the chat and Yaali, our AI agent, will pass your question to an engineer.
Sources: WatchGuard advisory CVE-2026-86131, WatchGuard advisory CVE-2026-81433, WatchGuard advisory CVE-2026-86101, SecurityWeek, SecurityOnline, OffSeq Threat Radar, Mallory, WatchGuard: About BOVPN over TLS, WatchGuard: Configure BOVPN over TLS in Client Mode.
Read next
- Chrome 154 and Firefox 157 fix 108 flaws: patch and relaunch
- Cisco SD-WAN Manager flaw gives admin API with no login
- Google: CVEs doubled in 2026 and AI finds riskier flaws
Back to the blog, or tell us about your system in the chat. Yaali, our AI agent, answers first and brings in an engineer.