CVE-2026-86131Critical· 9.2▾ MidnightA code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 50.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.
fireware_os >= 2026.3 < 2026.3.2fireware_os >= 2025.0 < 2026.2.3fireware_os >= 12.0 < 12.12.3fireware_os >= 12.0 < 12.5.21Fireware OS 2026.3.2, Fireware OS 2026.2.3, Fireware OS 12.12.3, Fireware OS 12.5.21
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-81433High· 8.7Fireware OS Pre-Authentication Stack Buffer Overflow in fingerd Allows Remote Code Execution
CVE-2026-86128High· 8.2Fireware OS NULL Pointer Dereference in NetFlow IPv6 Traffic Processing Allows Remote Denial of Service
CVE-2026-86101High· 7.2Fireware OS Authorization Bypass in SAML Login Allows Unauthorized SSLVPN Access
CVE-2026-86136High· 7.1Fireware OS Missing Authorization in wgagent Management API Allows Denial of Service - Variant A
CVE-2026-18145High· 8.6Fireware OS Stack-based Buffer Overflow in spamd Allows Remote Code Execution
CVE-2026-86132High· 8.2Fireware OS Pre-Authentication Integer Underflow in iked Allows Denial of Service