Skip to content

CVE 2026 86131

psirt.watchguard.com • September 30, 2026

A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.

Weakness Type and Impact #

CWE CWE-94 Improper Control of Generation of Code ('Code Injection')

CWE CWE-295 Improper Certificate Validation

CWE CWE-829 Inclusion of Functionality from Untrusted Control Sphere

CAPEC CAPEC-94 Adversary in the Middle (AiTM)

CAPEC CAPEC-242 Code Injection

Exploitation Status #

View the canonical record on cve.org