Skip to content
WatchGuard Patches Critical Fireware OS Code Injection Vulnerability

WatchGuard Patches Critical Fireware OS Code Injection Vulnerability

Securityweek • September 30, 2026

WatchGuard on Tuesday announced fixes for 15 vulnerabilities in Fireware OS, including a critical-severity remote code execution (RCE) bug.

Tracked as CVE-2026-86131 (CVSS score of 9.2), the flaw is described as a code injection issue in how the operating system handles BOVPN over TLS client configurations.

Successful exploitation could allow a remote attacker who controls the remote VPN server to execute commands with root privileges on the connecting Firebox appliance.

The security weakness was resolved in Fireware OS versions 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21.

The security updates also resolve 13 high-severity vulnerabilities that could lead to RCE, authorization bypass, denial-of-service (DoS), unauthorized SSLVPN access, and arbitrary local file reads.

A medium-severity improper authorization issue leading to unauthorized access to web applications was also addressed.

Several of these security defects could be exploited by remote attackers without authentication.

The Fireware OS patches landed one day after WatchGuard rolled out fixes for two critical- and one high-severity Access Point flaws.

Tracked as CVE-2026-101891 and CVE-2026-86102 and affecting internal API services, the critical issues could be exploited to obtain a valid API session without authentication and execute arbitrary shell commands on the underlying OS.

The high-severity weakness is an OS command injection that requires administrative privileges for exploitation. All three vulnerabilities were resolved in WatchGuard AP version 3.4.8.

According to WatchGuard, it is not aware of any of these security issues being exploited in the wild. Additional information can be found on the company’s security advisories page.

Related: Chrome, Firefox Updates Patch Over 100 Vulnerabilities

Related: Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign

Related: Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug

Related: ‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration

Artificial Intelligence

Google: AI Is Changing the Pace and Profile of Vulnerability Discovery

Google’s analysis found that AI-discovered vulnerabilities are more likely to enable remote code execution.

Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks

Several security firms have confirmed seeing exploitation of the NetScaler vulnerabilities CVE-2026-88771 and CVE-2026-88772.

Chrome, Firefox Updates Patch Over 100 Vulnerabilities

Some of the flaws could allow remote attackers to execute arbitrary code or escape the browser sandbox.

High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL

Roughly a dozen vulnerabilities have been patched in each of the open source cryptographic libraries.

Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign

The extortion group has modified its exploit in new attacks targeting the PeopleSoft vulnerability CVE-2026-35273.

Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability

The company says the measure was precautionary and that it has no evidence of Kiteworks or customer systems being compromised.

Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug

Citrix has released patches for the critical NetScaler vulnerabilities tracked as CVE-2026-88771 and CVE-2026-88772.

Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks

CISA added CVE-2026-65660 to its KEV catalog, giving federal agencies a patching deadline of September 28.