WatchGuard Patches Three Critical Flaws That Could Hand Attackers Full Control of Firewalls and Access Points

A clutch of serious vulnerabilities in WatchGuard's networking gear could hand attackers root-level control of firewalls and wireless access points. Patches are out, but the window between disclosure and update is where organisations get hurt.

ThreatVectr Newsdesk· Editor: Lee Brown· 3 min read
A physical rack-mounted network firewall appliance with blinking status LEDs in a dimly lit server room, shot from a low angle looking up along the row of equip
Share

Key points

  • CVE-2026-86131, published 30 September 2026 with a CVSS score of 9.2, lets a malicious VPN server run any command it likes as the highest-privileged user on a WatchGuard Firebox appliance.
  • Two companion flaws in WatchGuard Access Points, CVE-2026-101891 and CVE-2026-86102, both scored 9.3, allowing an unauthenticated attacker with network access to seize control of the device.
  • Fireware OS fixes land in versions 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21; Access Point fixes land in version 3.4.8.
  • WatchGuard says none of the three critical flaws have been exploited in the wild, as of publication.
  • The flaws affect gear commonly used by small and mid-sized businesses to protect their entire office networks.

WatchGuard makes the firewalls and wireless access points that quietly guard the front doors of thousands of business networks. This week the company shipped patches for fifteen separate security flaws across those products, including three rated critical, meaning a successful attacker could take full control of the affected device without first needing a password.

How did the vulnerabilities work?

Each of the three critical flaws opens a different door, but all three lead to the same destination: complete control of the hardware.

The Firebox vulnerability, tracked as CVE-2026-86131, lives inside a feature called BOVPN over TLS, a way of creating an encrypted tunnel between two office locations over the internet. It's a code injection bug, meaning a server on the other end of that tunnel could feed the Firebox specially crafted instructions and the device would execute them as root, the highest-level account on any Unix-style system. An attacker running a fake or compromised VPN endpoint could, in theory, pivot straight through the firewall and into the network behind it.

The Access Point pair is blunter. CVE-2026-101891 is an improper access control flaw in an internal API service (a programming interface the device uses to manage itself): anyone on the same network segment, with no credentials at all, could grab a valid session token and authenticate as a legitimate administrator. That's where CVE-2026-86102 comes in, an OS command injection bug in the same service that lets the holder of such a session run arbitrary shell commands on the underlying operating system. The two chain neatly.

The Access Point pair carries more immediate risk than the Firebox flaw, because it requires no prior relationship with the target device. Any attacker who can reach the access point on the network can weaponise both bugs in sequence.

Should businesses be worried?

WatchGuard says it has no evidence of active exploitation, which matters but shouldn't be read as a grace period.

Adversaries already know the value of sitting inside a Firebox. Sandworm, the Russian military intelligence group tracked under that name by Mandiant and others, was publicly linked to Cyclops Blink malware that targeted Firebox devices in 2022. That campaign pre-dates these specific vulnerabilities, and our 17 September report on ransomware crews hitting unpatched WatchGuard firewalls found close to 9,000 devices still exposed online after a patch had already shipped. Organisations that treat this week's patches as optional are missing that pattern.

Alongside the three critical issues, WatchGuard also patched thirteen high-severity flaws covering remote code execution, authorisation bypass, denial-of-service, unauthorised VPN access, and arbitrary file reads, according to SecurityWeek's coverage of the advisories.

Flaw CVE ID CVSS Affected product Fix version
VPN code injection CVE-2026-86131 9.2 Fireware OS 2026.3.2 / 2026.2.3 / 12.12.3 / 12.5.21
AP API access control CVE-2026-101891 9.3 WatchGuard Access Points 3.4.8
AP command injection CVE-2026-86102 9.3 WatchGuard Access Points 3.4.8

If your office uses WatchGuard hardware, ask whoever manages your network whether the firmware versions listed above have been applied. That conversation should happen today, not next quarter.

© 2026 Threat Vectr