Summary
WatchGuard patched 15 Fireware OS vulnerabilities, the worst a critical code injection flaw (CVE-2026-86131) that lets a malicious remote BOVPN-over-TLS server run root commands on a connecting Firebox, along several pre-authentication remote code execution and DoS bugs in services such as fingerd, spamd, iked and samld.
Take Action:
If you run WatchGuard Firebox appliances, upgrade Fireware OS to a fixed version ASAP (2026.3.2, 2026.2.3, 12.12.3, or 12.5.21 on T15/T35). There are 15 flaws, including a critical one with no workaround, so prioritize devices that use Branch Office VPN over TLS. Until you patch, make sure the firewall's management interface is reachable only from trusted admin networks, and only connect VPN tunnels to servers you fully control.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)