WatchGuard Issues Critical Security Patches for Multiple Vulnerabilities in Firebox Appliances

September 30, 2026
WatchGuard Issues Critical Security Patches for Multiple Vulnerabilities in Firebox Appliances
  • WatchGuard released patches beyond the Fireware fixes, addressing three AP vulnerabilities (CVE-2026-101891, CVE-2026-86102, AP version 3.4.8) that include an OS command injection requiring admin privileges and an API session vulnerability.

  • Affected feature is BOVPN over TLS, which operates as a client-server model and can route VPN traffic over TCP port 443, useful in environments where IPsec is blocked.

  • WatchGuard says there are no known exploitations in the wild and directs readers to psirt.watchguard.com for advisories.

  • A high-severity flaw (CVE-2026-86101, CVSS 7.2) involves improper authorization in SAML login that could let a remote authenticated SAML user with Access Portal access obtain unauthorized Mobile VPN with SSL access via a crafted request.

  • Organizations should review their Fireware OS versions and prioritize the September 29, 2026 updates, especially where BOVPN over TLS is enabled.

  • There is a medium-severity improper authorization issue that could grant unauthorized access to web applications, addressed in the updates.

  • Another patched issue (CVE-2026-81433, CVSS 8.7) is a stack-based buffer overflow in the fingerd DHCP fingerprinting daemon that can be triggered by crafted DHCP packets to execute code or crash the service.

  • A critical flaw involves code injection in BOVPN Over TLS client configuration handling, enabling arbitrary root commands on the Firebox without user interaction or prior privileges, effectively granting root access.

  • Relatedly, the same critical flaw concerns code injection in how Fireware OS handles BOVPN over TLS client configurations, potentially granting root privileges on the Firebox appliance.

  • Several vulnerabilities could be exploited remotely without authentication, and WatchGuard noted no known active exploitation at disclosure time.

  • WatchGuard reiterates there is no known active exploitation in the wild and urges customers to update affected Firebox appliances to patched releases.

  • The advisory also references security sources and provides links to WatchGuard PSIRT entries for each CVE detail.

Summary based on 2 sources


Get a daily email with more Tech stories

More Stories