WatchGuard Issues Critical Security Patches for Multiple Vulnerabilities in Firebox Appliances
September 30, 2026
WatchGuard released patches beyond the Fireware fixes, addressing three AP vulnerabilities (CVE-2026-101891, CVE-2026-86102, AP version 3.4.8) that include an OS command injection requiring admin privileges and an API session vulnerability.
Affected feature is BOVPN over TLS, which operates as a client-server model and can route VPN traffic over TCP port 443, useful in environments where IPsec is blocked.
WatchGuard says there are no known exploitations in the wild and directs readers to psirt.watchguard.com for advisories.
A high-severity flaw (CVE-2026-86101, CVSS 7.2) involves improper authorization in SAML login that could let a remote authenticated SAML user with Access Portal access obtain unauthorized Mobile VPN with SSL access via a crafted request.
Organizations should review their Fireware OS versions and prioritize the September 29, 2026 updates, especially where BOVPN over TLS is enabled.
There is a medium-severity improper authorization issue that could grant unauthorized access to web applications, addressed in the updates.
Another patched issue (CVE-2026-81433, CVSS 8.7) is a stack-based buffer overflow in the fingerd DHCP fingerprinting daemon that can be triggered by crafted DHCP packets to execute code or crash the service.
A critical flaw involves code injection in BOVPN Over TLS client configuration handling, enabling arbitrary root commands on the Firebox without user interaction or prior privileges, effectively granting root access.
Relatedly, the same critical flaw concerns code injection in how Fireware OS handles BOVPN over TLS client configurations, potentially granting root privileges on the Firebox appliance.
Several vulnerabilities could be exploited remotely without authentication, and WatchGuard noted no known active exploitation at disclosure time.
WatchGuard reiterates there is no known active exploitation in the wild and urges customers to update affected Firebox appliances to patched releases.
The advisory also references security sources and provides links to WatchGuard PSIRT entries for each CVE detail.
Summary based on 2 sources
Get a daily email with more Tech stories
Sources

SecurityWeek • Sep 30, 2026
WatchGuard Patches Critical Fireware OS Code Injection Vulnerability
Security Affairs • Sep 30, 2026
WatchGuard fixes critical Fireware OS flaw allowing remote code execution