Skip to content
WatchGuard Patches Critical RCE Vulnerability in Fireware OS

WatchGuard Patches Critical RCE Vulnerability in Fireware OS

First seen 30 Sep 2026, 16:28 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 30, 2026 at 17:31 UTC
  • •WatchGuard patched a critical RCE vulnerability in Fireware OS (CVE-2026-86131).
  • •The flaw allows remote command execution with root privileges via compromised VPN servers.
  • •Patches were released for multiple versions of Fireware OS and Access Point services.

On September 30, 2026, WatchGuard announced patches for 15 vulnerabilities in Fireware OS, including a critical remote code execution (RCE) vulnerability tracked as CVE-2026-86131, which has a CVSS score of 9.2. This flaw allows a remote attacker controlling a VPN server to execute commands with root privileges on the Firebox appliance. The vulnerabilities were addressed in Fireware OS versions 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21. Additionally, 13 high-severity vulnerabilities were patched, which could lead to RCE, authorization bypass, denial-of-service, and unauthorized SSLVPN access. WatchGuard also fixed two critical and one high-severity vulnerabilities in its Access Point services, tracked as CVE-2026-101891 and CVE-2026-86102. The company stated it is unaware of any exploitation of these vulnerabilities in the wild.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-06-11
CVE-2026-35273 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-11
CVE-2026-65660 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-27
CVE-2026-88772 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-27
CVE-2026-88771 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-28
CVE-2026-101891 and CVE-2026-86102 published
WatchGuard disclosed two critical vulnerabilities affecting Access Point services, allowing unauthorized API access and command execution.
Securityweek
2026-09-29
CVE-2026-86131 published
WatchGuard disclosed a critical RCE vulnerability in Fireware OS, allowing remote attackers to execute commands with root privileges.
Securityweek
2026-09-30
Patches released for Fireware OS
WatchGuard announced fixes for 15 vulnerabilities in Fireware OS, including the critical RCE flaw.
Securityweek

More articles in this cluster (2)

Following this threat?

Track CVE-2026-101891 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed