Securityweek WatchGuard Patches Critical RCE Vulnerability in Fireware OS
Article Content
- •WatchGuard patched a critical RCE vulnerability in Fireware OS (CVE-2026-86131).
- •The flaw allows remote command execution with root privileges via compromised VPN servers.
- •Patches were released for multiple versions of Fireware OS and Access Point services.
On September 30, 2026, WatchGuard announced patches for 15 vulnerabilities in Fireware OS, including a critical remote code execution (RCE) vulnerability tracked as CVE-2026-86131, which has a CVSS score of 9.2. This flaw allows a remote attacker controlling a VPN server to execute commands with root privileges on the Firebox appliance. The vulnerabilities were addressed in Fireware OS versions 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21. Additionally, 13 high-severity vulnerabilities were patched, which could lead to RCE, authorization bypass, denial-of-service, and unauthorized SSLVPN access. WatchGuard also fixed two critical and one high-severity vulnerabilities in its Access Point services, tracked as CVE-2026-101891 and CVE-2026-86102. The company stated it is unaware of any exploitation of these vulnerabilities in the wild.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-101891 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Vulnerabilities Patched in OpenSSL and WolfSSL On September 30, 2026, OpenSSL and WolfSSL developers released patches for multiple vulnerabilities, including high-severity flaws. OpenSSL addressed 14 vulnerabilities, with CVE-2026-84782 allowing remote peers to access heap memory fragments during DTLS handshakes, rated CVSS 8.2. WolfSSL patched 11 vulnerabilities…
Critical Command Injection and Authentication Flaws in WatchGuard Access Points Three critical vulnerabilities have been identified in WatchGuard's access points, allowing attackers to execute arbitrary commands and bypass authentication. The flaws include CVE-2026-101891, which permits unauthenticated access to a valid API session, and CVE-2026-86102, enabling command injection through the…