CVE-2026-86131

Published Sep 30, 2026

Last updated 8 hours ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-86131 is a code injection vulnerability found in WatchGuard Fireware OS, specifically within its Branch Office VPN (BOVPN) Over TLS client configuration handling. The flaw allows an attacker who controls the remote VPN server to execute arbitrary commands with root privileges on the connecting Firebox appliance. Exploitation of this vulnerability does not require any user interaction or prior privileges. The affected BOVPN over TLS feature operates on a client-server model, typically routing VPN traffic over TCP port 443 to bypass standard network firewalls. WatchGuard has addressed this issue by releasing security updates. The vulnerability is resolved in Fireware OS versions 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21.

Description
A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.
Source
5d1c2695-1a31-4499-88ae-e847036fd7e3
NVD status
Awaiting Analysis

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.2
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

Weaknesses

5d1c2695-1a31-4499-88ae-e847036fd7e3
CWE-94

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

2

References

Sources include official advisories and independent security research.