WatchGuard Fireware CVE-2026-86131: Patch Critical BOVPN over TLS Root RCE
WatchGuard has fixed CVE-2026-86131, a critical code-injection vulnerability in Fireware OS's BOVPN over TLS client configuration handling. The flaw carries a CVSS 4.0 score of 9.2 and can let an attacker who controls the remote VPN server execute arbitrary commands as root on a Firebox that connects to it.
The fixed releases are Fireware OS 2026.3.2, 2026.2.3, 12.12.3 and 12.5.21 for their respective supported release lines. Administrators using BOVPN over TLS client configurations should identify the Fireware train on each affected appliance and move to the corresponding fixed release.
The attack condition matters for exposure assessment: the vulnerable Firebox acts as the BOVPN over TLS client, and exploitation requires control of the remote VPN server it connects to. This is therefore a high-impact trust-boundary failure in the VPN-client configuration path, with root-level consequences once the required peer-control condition is met.
Fixed versions
| Fireware OS line | Affected range | Fixed release |
|---|---|---|
| 2026.3 | Earlier than 2026.3.2 | 2026.3.2 |
| 2025.0 / 2026.2 | Earlier than 2026.2.3 | 2026.2.3 |
| 12.x maintained line | Earlier than 12.12.3 | 12.12.3 |
| 12.5 line for T15/T35 | Earlier than 12.5.21 | 12.5.21 |
WatchGuard's advisory is the authoritative source for the applicable branch and appliance support status. SecurityWeek independently reports the same four remediation releases and the CVSS 9.2 rating.
What CVE-2026-86131 allows
The vulnerability is in processing configuration supplied through the BOVPN over TLS client relationship. According to WatchGuard, a party controlling the remote VPN server can use the vulnerable handling path to inject commands that execute as root on the connecting Firebox.
That privilege level makes successful exploitation a full appliance-compromise event. A compromised firewall can expose network policy, credentials and traffic-management functions, so remediation should be prioritized for deployments that use this VPN mode or have connected to a peer whose integrity is uncertain.
The peer-control requirement also gives operators a useful inventory question: identify Fireboxes configured as BOVPN over TLS clients and verify which remote endpoints they trust. Appliances that do not use the affected client configuration do not share the documented attack path, although they should still receive supported Fireware security maintenance.
Patch and verification checklist
- Inventory Fireboxes and record their current Fireware OS release.
- Identify appliances configured as BOVPN over TLS clients and the remote VPN servers they connect to.
- Upgrade each affected release train to its fixed floor or a newer supported release: 2026.3.2, 2026.2.3, 12.12.3 or 12.5.21 as applicable.
- Reconfirm the identity and administrative control of configured remote BOVPN over TLS peers.
- Review appliance administration and configuration records for unexpected changes when a Firebox has connected to a peer that may have been compromised.
- Validate VPN operation and policy after the update using the organization's normal change-control procedure.
Exploitation status
WatchGuard said at disclosure that it was not aware of exploitation in the wild for the vulnerabilities in this Fireware security release. CVE-2026-86131 was also not listed in CISA's Known Exploited Vulnerabilities catalog at the time of this review.
Those status signals describe observed exploitation, while the vendor-rated impact remains critical. The fixed releases are available, and the documented prerequisite—control of the remote VPN server—provides the main exposure boundary for prioritization.
Broader Fireware security release
CVE-2026-86131 arrived as part of a larger Fireware OS security update. WatchGuard addressed multiple additional high-severity issues involving remote code execution, authorization, denial of service, SSLVPN access and local file reads. Administrators should treat the fixed Fireware release as a cumulative security update and review the vendor's PSIRT index for other advisories relevant to enabled services.
Bottom line
Fireboxes that operate as BOVPN over TLS clients should be upgraded to the fixed Fireware release for their branch. CVE-2026-86131 gives a malicious or compromised remote VPN server a path to root command execution on a vulnerable connecting appliance, making peer trust and patch level the two central controls.
Sources
- WatchGuard PSIRT — CVE-2026-86131: https://psirt.watchguard.com/CVE-2026-86131/
- WatchGuard PSIRT advisory index: https://psirt.watchguard.com/
- SecurityWeek — WatchGuard Patches Critical Fireware OS Code Injection Vulnerability: https://www.securityweek.com/watchguard-patches-critical-fireware-os-code-injection-vulnerability/
- CVE.org — CVE-2026-86131: https://www.cve.org/CVERecord?id=CVE-2026-86131