[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fMKI3SmAaPmgfmCMZfw6IYxJFGGATbn9SkAV4rnEaaSg":3},{"article":4,"iocs":41},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":28,"category":29,"article_tags":33},"07ac3e59-b1c0-478a-ba1b-4ce18dc3905c","WatchGuard Patches Critical Fireware OS Code Injection Vulnerability","watchguard-patches-critical-fireware-os-code-injection-vulnerability-c17c63","WatchGuard has rolled out patches for 15 code execution, DoS, authorization, and path traversal bugs in Fireware OS. The post WatchGuard Patches Critical Fireware OS Code Injection Vulnerability appeared first on SecurityWeek.","WatchGuard released security updates addressing 15 vulnerabilities in Fireware OS, highlighted by a critical-severity remote code injection vulnerability (CVE-2026-86131, CVSS 9.2) affecting BOVPN over TLS client configurations. The flaw allows unauthenticated remote attackers controlling a VPN server to execute commands with root privileges on Firebox appliances. Additionally, WatchGuard patched three vulnerabilities in its Access Points, including two critical API authentication bypasses and one OS command injection flaw.","WatchGuard patches 15 vulnerabilities in Fireware OS, including critical RCE flaw CVE-2026-86131 with CVSS 9.2","WatchGuard on Tuesday announced fixes for 15 vulnerabilities in Fireware OS, including a critical-severity remote code execution (RCE) bug. Tracked as CVE-2026-86131 (CVSS score of 9.2), the flaw is described as a code injection issue in how the operating system handles BOVPN over TLS client configurations. Successful exploitation could allow a remote attacker who controls the remote VPN server to execute commands with root privileges on the connecting Firebox appliance. The security weakness was resolved in Fireware OS versions 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21. The security updates also resolve 13 high-severity vulnerabilities that could lead to RCE, authorization bypass, denial-of-service (DoS), unauthorized SSLVPN access, and arbitrary local file reads. A medium-severity improper authorization issue leading to unauthorized access to web applications was also addressed.Advertisement. Scroll to continue reading. Several of these security defects could be exploited by remote attackers without authentication. The Fireware OS patches landed one day after WatchGuard rolled out fixes for two critical- and one high-severity Access Point flaws. Tracked as CVE-2026-101891 and CVE-2026-86102 and affecting internal API services, the critical issues could be exploited to obtain a valid API session without authentication and execute arbitrary shell commands on the underlying OS. The high-severity weakness is an OS command injection that requires administrative privileges for exploitation. All three vulnerabilities were resolved in WatchGuard AP version 3.4.8. According to WatchGuard, it is not aware of any of these security issues being exploited in the wild. Additional information can be found on the company’s security advisories page. Related: Chrome, Firefox Updates Patch Over 100 Vulnerabilities Related: Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign Related: Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug Related: ‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Reco Raises $55 Million for Agentic SecurityHackers Use ChatGPT Custom GPTs in ClickFix AttacksDutch Police Arrest Convicted Hacker in ShinyHunters InvestigationDaemon Tools Hackers’ NeedyMantis Malware Dissected by MicrosoftPrison Sentence for Former US Soldier Who Hacked AT&T and VerizonDC Health Agency Exposes 400,000 Beneficiary RecordsGoogle Warns of ShinyHunters’ Fresh Oracle PeopleSoft CampaignKiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability Latest News Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day AttacksChrome, Firefox Updates Patch Over 100 VulnerabilitiesAnthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking LawsuitRussian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent AttacksShinyHunters Defiant After FBI Calls on Members to Come ForwardHigh-Severity Vulnerabilities Patched in OpenSSL, WolfSSLTrump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI DevelopmentOpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer Conference Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the Move David Cass has joined Grayscale Investments as Chief Risk Officer. He joins the crypto investment funds firm from Keyrock, where he served as Chief Information Security Officer. Thomas Dager has been appointed Vice President and Chief Information Security Officer at The Goodyear Tire & Rubber Company.Alex Stamos has become Chief Information Security Officer at Cognition.More People On The MoveExpert Insights Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fwatchguard-patches-critical-fireware-os-code-injection-vulnerability\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2026\u002F04\u002Fcoding-vulnerability-software-development.jpeg","2026-09-30T13:16:56+00:00","2026-09-30T14:00:32.838105+00:00",9,[18,21,24,26],{"name":19,"type":20},"WatchGuard","vendor",{"name":22,"type":23},"Fireware OS","product",{"name":25,"type":23},"WatchGuard Access Point",{"name":27,"type":23},"Firebox","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":28,"icon":30,"name":31,"slug":32},null,"Vulnerabilities","vulnerabilities",[34,39],{"category":35},{"id":36,"icon":30,"name":37,"slug":38},"574f766a-fb3f-487c-8d2c-0720ae75471b","Zero-day","zero-day",{"category":40},{"id":28,"icon":30,"name":31,"slug":32},[42,46,49],{"type":43,"value":44,"context":45},"cve","CVE-2026-86131","Critical remote code injection in Fireware OS BOVPN over TLS client configurations, CVSS 9.2",{"type":43,"value":47,"context":48},"CVE-2026-101891","Critical unauthenticated API session bypass in WatchGuard Access Point",{"type":43,"value":50,"context":51},"CVE-2026-86102","Critical arbitrary shell command execution via internal API services in WatchGuard Access Point"]