INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
WatchGuard Fixes Critical Fireware OS Flaw for Remote Code Execution
| 2026-09-30 13:16 CRITICAL MEDIUM VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
WatchGuard has released security updates for Fireware OS that address 15 vulnerabilities, including a critical code injection flaw (CVE-2026-86131) tracked as CVSS score of 9.2, allowing an attacker to execute commands with root privileges on a vulnerable Firebox. The flaws include remote code execution, authorization bypass, denial-of-service conditions, unauthorized SSLVPN access and arbitrary file reads. ShinyHunters, an APT group, is believed to be behind the attack. WatchGuard has patched these vulnerabilities in versions 2026.3.2, 2026.2.3, 12.12.3 and 12.5.21 of Fireware OS. This incident highlights the importance of regular software updates and patching to prevent such attacks.
Technical Mitigations AI-generated
• Implement a network segmentation strategy to limit the attack surface of Firebox appliances, reducing the potential impact of an attacker controlling the remote VPN server.
• Configure BOVPN over TLS clients with strict access controls and authentication mechanisms to prevent unauthorized access and code injection vulnerabilities.
• Regularly update Fireware OS to version 2026.3.2 or later, as well as other affected branches, to patch known vulnerabilities and reduce the risk of exploitation.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
CVE-2026-86131CVE-2026-86131
CVE-2026-81433CVE-2026-81433
CVE-2026-101891CVE-2026-101891
CVE-2026-86102CVE-2026-86102
CVE-2026-86101CVE-2026-86101
Target & Sectors
Global Scope
Incident Timeline
2026.2.3
WatchGuard addressed the CVE-2026-86131 code injection vulnerability in Fireware OS versions 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21 starting with version 2026.3.2 on 2026.2.3.
Click on any entity below to view its context and source!
infrastructure
2026.3.2
The security weakness was resolved in Fireware OS versions 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21.
infrastructure
2026.2.3
The security weakness was resolved in Fireware OS versions 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21.
infrastructure
12.12.3
The security weakness was resolved in Fireware OS versions 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21.
infrastructure
12.5.21
The security weakness was resolved in Fireware OS versions 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21.
vulnerability
CVE-2026-86131
WatchGuard addressed CVE-2026-86131 in Fireware OS 2026.3.2, 2026.2.3, 12.12.3 and 12.5.21.
September 29
WatchGuard has released security updates for its Fireware OS on September 29 to address a critical code injection vulnerability.
September 30, 2026
WatchGuard patches a critical Fireware OS code injection vulnerability, allowing remote code execution.
Click on any entity below to view its context and source!
tactic
Remote Code Execution
WatchGuard fixes critical Fireware OS flaw allowing remote code execution
Pierluigi Paganini
September 30, 2026
2026/09/30
WatchGuard has released security updates for Fireware OS that address 15 vulnerabilities, including a critical code injection flaw tracked as CVE-2026-86131 with a CVSS score of 9.2.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
Related:
Chrome, Firefox Updates Patch Over 100 Vulnerabilities
Related:
Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
Related:
Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug
Related:
‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration
organisation
PeopleSoft
Related:
Chrome, Firefox Updates Patch Over 100 Vulnerabilities
Related:
Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
Related:
Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug
Related:
‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration
organisation
Zero-Click Data Exfiltration
Related:
Chrome, Firefox Updates Patch Over 100 Vulnerabilities
Related:
Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
Related:
Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug
Related:
‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration
organisation
WatchGuard
WatchGuard on Tuesday announced fixes for 15 vulnerabilities in Fireware OS, including a critical-severity remote code execution (RCE) bug.
WatchGuard fixes critical Fireware OS flaw allowing remote code execution.
organisation
Fireware
WatchGuard on Tuesday announced fixes for 15 vulnerabilities in Fireware OS, including a critical-severity remote code execution (RCE) bug.
WatchGuard fixes critical Fireware OS flaw allowing remote code execution.
organisation
CVE-2026-86131
WatchGuard has released security updates for Fireware OS that
address 15 vulnerabilities
, including a critical code injection flaw, tracked as CVE-2026-86131 (CVSS score of 9.2), that could allow an attacker to execute commands with root privileges on a vulnerable Firebox.
infrastructure
9.2
WatchGuard has released security updates for Fireware OS that
address 15 vulnerabilities
, including a critical code injection flaw, tracked as CVE-2026-86131 (CVSS score of 9.2), that could allow an attacker to execute commands with root privileges on a vulnerable Firebox.
organisation
Firebox
WatchGuard fixes 15 Fireware OS flaws, including a critical RCE bug that could give attackers root access to vulnerable Firebox appliances.
Successful exploitation could allow a remote attacker who controls the remote VPN server to execute commands with root privileges on the connecting Firebox appliance.
organisation
TLS
Tracked as CVE-2026-86131 (CVSS score of 9.2), the flaw is described as a code injection issue in how the operating system handles BOVPN over TLS client configurations.
The flaw affects the way Fireware OS handles configurations for BOVPN over TLS clients, a feature used to create VPN tunnels between WatchGuard Firebox appliances.
organisation
WatchGuard Firebox
The flaw affects the way Fireware OS handles configurations for BOVPN over TLS clients, a feature used to create VPN tunnels between WatchGuard Firebox appliances.
organisation
Access Point
The Fireware OS patches landed one day after WatchGuard rolled out fixes for two critical- and one high-severity Access Point flaws.
Tracked as CVE-2026-101891 and CVE-2026-86102 and affecting internal API services, the critical issues could be exploited to obtain a valid API session without authentication and execute arbitrary shell commands on the underlying OS.
organisation
CVE-2026
The Fireware OS patches landed one day after WatchGuard rolled out fixes for two critical- and one high-severity Access Point flaws.
Tracked as CVE-2026-101891 and CVE-2026-86102 and affecting internal API services, the critical issues could be exploited to obtain a valid API session without authentication and execute arbitrary shell commands on the underlying OS.
organisation
API
The Fireware OS patches landed one day after WatchGuard rolled out fixes for two critical- and one high-severity Access Point flaws.
Tracked as CVE-2026-101891 and CVE-2026-86102 and affecting internal API services, the critical issues could be exploited to obtain a valid API session without authentication and execute arbitrary shell commands on the underlying OS.
infrastructure
3.4.8
All three vulnerabilities were resolved in WatchGuard AP version 3.4.8.
organisation
WatchGuard AP
All three vulnerabilities were resolved in WatchGuard AP version 3.4.8.
organisation
RCE
The security updates also resolve 13 high-severity vulnerabilities that could lead to RCE, authorization bypass, denial-of-service (DoS), unauthorized SSLVPN access, and arbitrary local file reads.
organisation
DoS
The security updates also resolve 13 high-severity vulnerabilities that could lead to RCE, authorization bypass, denial-of-service (DoS), unauthorized SSLVPN access, and arbitrary local file reads.
organisation
DHCP
Another patched issue allows an attacker with adjacent network access to send specially crafted DHCP traffic that can trigger a stack-based buffer overflow in the
fingerd
process.
organisation
CVE-2026-81433
The flaw, tracked as CVE-2026-81433 (CVSS score of 8.7), can lead to arbitrary code execution or a crash.
organisation
WatchGuard Fireware OS’s
“A code injection vulnerability in WatchGuard Fireware OS’s BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.”
reads the advisory
.
organisation
IPsec
This makes the feature useful in environments where traditional IPsec traffic cannot easily pass through the network.
organisation
SSL
A remote authenticated SAML user with access to the Access Portal could abuse a specially crafted request to obtain unauthorized Mobile VPN with SSL access.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Fireware OS)
Tactical Metrics
Metrics
infrastructure
2026.3.2
Software Version
Click for context!
The security weakness was resolved in Fireware OS versions 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21.
Metrics
infrastructure
2026.2.3
Software Version
The security weakness was resolved in Fireware OS versions 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21.
Metrics
infrastructure
12.12.3
Software Version
The security weakness was resolved in Fireware OS versions 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21.
Metrics
infrastructure
12.5.21
Software Version
The security weakness was resolved in Fireware OS versions 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21.
Metrics
infrastructure
3.4.8
Software Version
All three vulnerabilities were resolved in WatchGuard AP version 3.4.8.
Metrics
infrastructure
9.2
Software Version
WatchGuard has released security updates for Fireware OS that
address 15 vulnerabilities
, including a critical code injection flaw, tracked as CVE-2026-86131 (CVSS score of 9.2), that could allow an attacker to execute commands with root privileges on a vulnerable Firebox.
Intelligence Sources
Security Affairs
2026-09-30
SecurityWeek
2026-09-30
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T06:30
Comprehensive Tactical Telemetry
Highly Correlated Entities
21x
organisation
Identified Entity
PeopleSoft
entity
6x
infrastructure
Software Version
2026.3.2
version
5x
vulnerability
Exploited CVE
CVE-2026-86131
cve
4x
timeline
Temporal Reference
2026.2.3
date
3x
tactic
Cyber Operation Type
Exfiltration
tactic
3x
vulnerability
CVSS Score
9
score
2x
general metric
Vulnerabilities
100
vulnerabilities
Contextual Telemetry
Context Block
5 METRICS
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
threat actor
APT Group
ShinyHunters
actor
general metric
Netscaler Zero Days
2
netscaler zero days
general metric
Severity Vulnerabilities
13
severity vulnerabilities
general metric
Tcp Port
443
tcp port
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.