• PATCH AVAILABLE

CVE-2026-86131: remote code execution in WatchGuard Fireware OS

A remote attacker who controls a BOVPN Over TLS server can execute arbitrary commands as root on a connecting WatchGuard Fireware OS device (CVE-2026-86131). Affected releases include 2026.3 before 2026.3.2, 2025.0 before 2026.2.3, and 12.0 branches before 12.12.3 and 12.5.21. The attacker only needs the Firebox to initiate a BOVPN Over TLS connection to a malicious or compromised VPN server.

Published Updated Source: CVE Program, NVD, Vendor advisory

CVSS 4.0
9.2CRITICAL
EPSS
n/a
CWE
CWE-295
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent — this is a remote root code execution triggered by a malicious BOVPN Over TLS server and fixed builds are available; prioritize installing the listed fixes or block untrusted BOVPN endpoints immediately.

What is CVE-2026-86131?

A remote attacker who controls a BOVPN Over TLS server can execute arbitrary commands as root on a connecting WatchGuard Fireware OS device (CVE-2026-86131). Affected releases include 2026.3 before 2026.3.2, 2025.0 before 2026.2.3, and 12.0 branches before 12.12.3 and 12.5.21. The attacker only needs the Firebox to initiate a BOVPN Over TLS connection to a malicious or compromised VPN server. The weakness is classified as CWE-295 (Improper Certificate Validation).

Vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Which versions of WatchGuard Fireware OS are affected?

BRANCHAFFECTEDFIXED
2026.x2026.3 – before 2026.3.22026.3.2
2026.x2025.0 – before 2026.2.32026.2.3
12.x12.0 – before 12.12.312.12.3
12.x12.0 – before 12.5.2112.5.21

Is CVE-2026-86131 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-86131

  1. Upgrade Fireware OS to the fixed releases (2026.3.2, 2026.2.3, 12.12.3, or 12.5.21) as appropriate for your branch.
  2. Restrict BOVPN Over TLS peer endpoints to trusted servers and validate server identities before allowing connections.
  3. Block or firewall outbound BOVPN connections from devices that do not require them and monitor VPN connection logs for unexpected peers.
  4. Follow WatchGuard guidance and review device logs for signs of compromise if untrusted BOVPN connections occurred.

Frequently asked questions

Is CVE-2026-86131 being actively exploited?

There are no public reports of exploitation of CVE-2026-86131 as of 2026-09-30.

Which WatchGuard Fireware OS versions are affected by CVE-2026-86131?

Affected Fireware OS releases include 2026.3 before 2026.3.2, 2025.0 before 2026.2.3, and 12.0 branch releases before 12.12.3 and 12.5.21.

Is there a patch for CVE-2026-86131?

Yes; WatchGuard released fixed builds: 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21 for the respective affected branches.

Does CVE-2026-86131 require authentication?

No authentication on the Firebox is required beyond the device initiating a BOVPN Over TLS connection to a malicious or controlled VPN server; the vulnerability is triggered by the remote server during connection.

References