CVE 2026 86131
A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.
Weakness Type and Impact #
CWE CWE-94 Improper Control of Generation of Code ('Code Injection')
CWE CWE-295 Improper Certificate Validation
CWE CWE-829 Inclusion of Functionality from Untrusted Control Sphere
CAPEC CAPEC-94 Adversary in the Middle (AiTM)
CAPEC CAPEC-242 Code Injection
Exploitation Status #
View the canonical record on cve.org
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
