Vulnerabilities fixed in Fireware OS: 15 (Source: SecurityWeek (September 30, 2026))
The guard that has to distrust the servers it calls
We usually picture a firewall as a guard facing outward. It checks who wants in. A flaw WatchGuard fixed this week shows the other half of the job. The guard also has to distrust the places it chooses to call.
WatchGuard announced on Tuesday a patch bundle for Fireware OS, the software running its Firebox appliances. It covers 15 security flaws. SecurityWeek reported the news. The most serious is CVE-2026-86131, rated 9.2 on the CVSS severity scale. It is a code injection flaw in how the system handles BOVPN over TLS client configurations.
How the flaw works
Code injection means a system treats data it received as instructions to run. In this case, the flaw sits in how the Firebox handles client configurations for BOVPN over TLS tunnels. TLS is the same encryption used by secure websites.
The Firebox is the connecting device. It dials out to a remote VPN server. According to the report, an attacker who controls that remote server could make the Firebox run commands with root privileges. Root is the highest level of access on the device. The attacker's route is through the server the Firebox connects to.
The limit matters. The attacker must control the server at the other end of the tunnel. The report does not say how likely that is in practice.
The consequence is still clear. Root control of a network edge device means control of the machine that sits between an internal network and the outside world.
Not the only flaw in this batch
The same update fixes 13 high-severity flaws. They could lead to remote code execution, authorization bypass, denial of service, unauthorized SSLVPN access and arbitrary reads of local files. One medium-severity flaw allowed unauthorized access to web applications.
Some of the bugs can be triggered by an outside attacker who has no credentials, SecurityWeek says. It does not name which ones.
Four releases carry the fixes: 12.5.21, 12.12.3, 2026.2.3 and 2026.3.2.
A second patch a day earlier
One day before, WatchGuard fixed three flaws in its Access Point products. Two are rated critical: CVE-2026-101891 and CVE-2026-86102. They affect internal API services. Together they could let an attacker get a valid API session without logging in and then run arbitrary shell commands on the underlying system.
The third is a high-severity command injection that needs administrator rights. All three are fixed in WatchGuard AP version 3.4.8.
WatchGuard says it is not aware of any of these flaws being exploited in the wild. That reflects what the company knows today. It is not proof that no one is trying.
What this shows
This is one vendor and two patch releases. It does not prove a trend. It does show something worth planning around: security devices carry a lot of trust and run a lot of code.
A firewall is often treated as the fix. This case shows it is also software that processes input from outside. In this flaw, the attacker's route runs through a server the device connects to.
The people who feel this are network administrators. They face two patch releases in two days across different product lines. Each one means finding every affected device and updating it.
Questions to put to your team
Ask which Firebox appliances the organization runs and which Fireware OS version each one uses. Then check each against the patched releases named above.
Ask whether any device uses BOVPN over TLS as a client. If so, ask who operates the server at the other end, and whether your team controls it.
Ask the same inventory question for WatchGuard access points and version 3.4.8. Then ask who owns the update and by what date it will be done.
A firewall protects the network only as far as its own code can be trusted. Patch the guard, and check who it is talking to.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: SecurityWeek.





