DIRAS TAKE
Urgent — this is a remote root code execution triggered by a malicious BOVPN Over TLS server and fixed builds are available; prioritize installing the listed fixes or block untrusted BOVPN endpoints immediately.
What is CVE-2026-86131?
A remote attacker who controls a BOVPN Over TLS server can execute arbitrary commands as root on a connecting WatchGuard Fireware OS device (CVE-2026-86131). Affected releases include 2026.3 before 2026.3.2, 2025.0 before 2026.2.3, and 12.0 branches before 12.12.3 and 12.5.21. The attacker only needs the Firebox to initiate a BOVPN Over TLS connection to a malicious or compromised VPN server. The weakness is classified as CWE-295 (Improper Certificate Validation).
Vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Which versions of WatchGuard Fireware OS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 2026.x | 2026.3 – before 2026.3.2 | 2026.3.2 |
| 2026.x | 2025.0 – before 2026.2.3 | 2026.2.3 |
| 12.x | 12.0 – before 12.12.3 | 12.12.3 |
| 12.x | 12.0 – before 12.5.21 | 12.5.21 |
Is CVE-2026-86131 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-86131
- Upgrade Fireware OS to the fixed releases (2026.3.2, 2026.2.3, 12.12.3, or 12.5.21) as appropriate for your branch.
- Restrict BOVPN Over TLS peer endpoints to trusted servers and validate server identities before allowing connections.
- Block or firewall outbound BOVPN connections from devices that do not require them and monitor VPN connection logs for unexpected peers.
- Follow WatchGuard guidance and review device logs for signs of compromise if untrusted BOVPN connections occurred.
Frequently asked questions
Is CVE-2026-86131 being actively exploited?
There are no public reports of exploitation of CVE-2026-86131 as of 2026-09-30.
Which WatchGuard Fireware OS versions are affected by CVE-2026-86131?
Affected Fireware OS releases include 2026.3 before 2026.3.2, 2025.0 before 2026.2.3, and 12.0 branch releases before 12.12.3 and 12.5.21.
Is there a patch for CVE-2026-86131?
Yes; WatchGuard released fixed builds: 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21 for the respective affected branches.
Does CVE-2026-86131 require authentication?
No authentication on the Firebox is required beyond the device initiating a BOVPN Over TLS connection to a malicious or controlled VPN server; the vulnerability is triggered by the remote server during connection.
References
- nvd.nist.gov/vuln/detail/CVE-2026-86131
- cve.org/CVERecord?id=CVE-2026-86131
- psirt.watchguard.com/CVE-2026-86131
- All WatchGuard CVEs on CVE Radar
- CVEs published in September 2026