CVE-2026-86131

Fireware OS Code Injection in BOVPN Over TLS Client Allows Remote Code Execution

Critical 9.2 CVSS v4.0 › Published 2026-09-29Updated 2026-09-29

Summary #

A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.

Product status #

ProductAffectedNot affected
Fireware OS
Default >= 2026.3, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3
T15/T35 >= 12.0, < 12.5.21>= 12.5.21

Weakness Type and Impact #

  • CWECWE-94Improper Control of Generation of Code ('Code Injection')
  • CWECWE-295Improper Certificate Validation
  • CWECWE-829Inclusion of Functionality from Untrusted Control Sphere
  • CAPECCAPEC-94Adversary in the Middle (AiTM)
  • CAPECCAPEC-242Code Injection

Exploitation Status #

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solution #

Fireware OS 2026.3.2, Fireware OS 2026.2.3, Fireware OS 12.12.3, Fireware OS 12.5.21

References #

    Credits #

    • btaolfinder