BlackTree Security · Infrastructure · Automation · AI

The VPN Server Your Firebox Trusts Could Hand It Root Commands

WatchGuard has patched 15 vulnerabilities across supported Fireware OS branches. The most serious one turns an expected trust relationship inside out: a hostile remote VPN server can send configuration that a connecting Firebox executes as root.

That is not an unrestricted internet takeover. An attacker must control the remote server used by a Firebox configured as a BOVPN over TLS client. But for organisations that use that topology, CVE-2026-86131 crosses one of the hardest security boundaries on the device.

WatchGuard fixed the issue in Fireware OS 2026.3.2, 2026.2.3 and 12.12.3. T15 and T35 appliances on the older branch need 12.5.21. The company says it is not aware of exploitation.

The same release closes 14 other flaws. They include adjacent-network code execution through DHCP fingerprinting, remote crashes in IKEv2 and NetFlow processing, local file disclosure through low-privilege management accounts, and access-control failures involving the Access Portal.

The topology condition should shape triage. Organisations that do not use a Firebox as a BOVPN over TLS client do not share the lead flaw’s direct exposure, while those that do should treat the remote server as part of the firewall’s privileged trust boundary. That means ownership, certificates, configuration history and administrative access to the server belong in the same review as the appliance patch.

Fifteen flaws, five remediation paths

WatchGuard’s advisories do not use one universal version matrix. Most appliances follow three current release branches, while T15 and T35 models usually require a separate 12.5.21 build. One SAML flaw also has an EUCC-specific fix, and the DHCP flaw does not list the T15/T35 branch.

Vulnerability What an attacker needs and what can happen Affected and fixed versions
CVE-2026-86134, CVSS 8.7 No authentication. A crafted login request can crash the management daemon. 2026.3 to before 2026.3.2; 2025.0 to before 2026.2.3; 12.0 to before 12.12.3; T15/T35 before 12.5.21. Fixes: 2026.3.2, 2026.2.3, 12.12.3 and 12.5.21.
CVE-2026-86104, CVSS 8.7 No authentication. A crafted request can exhaust resources in wgagent and cause denial of service. 2026.3 to before 2026.3.2; 2025.0 to before 2026.2.3; 12.0 to before 12.12.3; T15/T35 before 12.5.21. Fixes: 2026.3.2, 2026.2.3, 12.12.3 and 12.5.21.
CVE-2026-18145, CVSS 8.6 An authenticated administrator can send a crafted management request that crashes spamd or potentially executes code. 2026.3 to before 2026.3.2; 2025.0 to before 2026.2.3; 12.0 to before 12.12.3; T15/T35 before 12.5.21. Fixes: 2026.3.2, 2026.2.3, 12.12.3 and 12.5.21.
CVE-2026-13046, CVSS 7.5 The attacker must already be able to write files on the appliance. A malicious SAML session file can then execute code in samld. Common branches are fixed in 2026.3.2, 2026.2.3 and 12.12.3. EUCC 12.11 is affected before 12.11.10. WatchGuard’s product table marks 2026.3.2 as not affected, although its Solution field lists only 2026.2.3, 12.12.3 and 12.11.10.
CVE-2026-86101, CVSS 7.2 An authenticated SAML user limited to the Access Portal can gain unauthorised Mobile VPN with SSL access. 2026.3 to before 2026.3.2; 2025.0 to before 2026.2.3; 12.0 to before 12.12.3; T15/T35 before 12.5.21. Fixes: 2026.3.2, 2026.2.3, 12.12.3 and 12.5.21.
CVE-2026-86133, CVSS 8.2 A remote attacker must complete the initial IKEv2 handshake. A crafted encrypted message can then crash iked. 2026.3 to before 2026.3.2; 2025.0 to before 2026.2.3; 12.0 to before 12.12.3; T15/T35 before 12.5.21. Fixes: 2026.3.2, 2026.2.3, 12.12.3 and 12.5.21.
CVE-2026-13224, CVSS 8.2 An authenticated administrator can use path traversal in the WebUI management agent to read or list arbitrary local files. Current branches are fixed in 2026.3.2, 2026.2.3 and 12.12.3. The all-platform 12.0 line is affected before 12.5.21 and fixed in 12.5.21.
CVE-2026-86132, CVSS 8.2 No authentication. A crafted encrypted IKEv2 message negotiated with AES-GCM can crash iked. 2026.3 to before 2026.3.2; 2025.0 to before 2026.2.3; 12.0 to before 12.12.3; T15/T35 before 12.5.21. Fixes: 2026.3.2, 2026.2.3, 12.12.3 and 12.5.21.
CVE-2026-86105, CVSS 5.3 An authenticated low-privilege Access Portal user can reach web applications for which access was not authorised. 2026.3 to before 2026.3.2; 2025.0 to before 2026.2.3; 12.0 to before 12.12.3; T15/T35 before 12.5.21. Fixes: 2026.3.2, 2026.2.3, 12.12.3 and 12.5.21.
CVE-2026-90441, CVSS 7.1 An authenticated read-only or guest administrator can crash wgagent and read files available to the daemon through a crafted API request. 2026.3 to before 2026.3.2; 2025.0 to before 2026.2.3; 12.0 to before 12.12.3; T15/T35 before 12.5.21. Fixes: 2026.3.2, 2026.2.3, 12.12.3 and 12.5.21.
CVE-2026-86131, CVSS 9.2 The attacker must control the remote VPN server used by a BOVPN over TLS client. Malicious configuration can run commands as root on the connecting Firebox. 2026.3 to before 2026.3.2; 2025.0 to before 2026.2.3; 12.0 to before 12.12.3; T15/T35 before 12.5.21. Fixes: 2026.3.2, 2026.2.3, 12.12.3 and 12.5.21.
CVE-2026-86136, CVSS 7.1 An authenticated read-only or guest administrator can crash wgagent and read files available to it through a crafted API request. 2026.0 to before 2026.3.2; 2025.0 to before 2026.2.3; 12.0 to before 12.12.3; T15/T35 before 12.5.21. Fixes: 2026.3.2, 2026.2.3, 12.12.3 and 12.5.21.
CVE-2026-81433, CVSS 8.7 No authentication, but adjacent-network access is required. A crafted DHCP packet can crash the fingerprinting daemon or execute code. 2026.3 to before 2026.3.2; 2025.0 to before 2026.2.3; 12.0 to before 12.12.3. Fixes: 2026.3.2, 2026.2.3 and 12.12.3. No T15/T35 row is listed.
CVE-2026-86128, CVSS 8.2 No authentication. A crafted IPv6 packet can crash NetFlow packet processing. 2026.3 to before 2026.3.2; 2025.0 to before 2026.2.3; 12.0 to before 12.12.3; T15/T35 before 12.5.21. Fixes: 2026.3.2, 2026.2.3, 12.12.3 and 12.5.21.
CVE-2026-18105, CVSS 7.1 An authenticated low-privilege user can repeatedly start and abort a crafted diagnostic task through the web UI, disrupting diagnostic tools. 2026.3 to before 2026.3.2; 2025.0 to before 2026.2.3; 12.0 to before 12.12.3; T15/T35 before 12.5.21. Fixes: 2026.3.2, 2026.2.3, 12.12.3 and 12.5.21.

WatchGuard states that it knows of no exploitation for any of the 15 vulnerabilities. A bounded search found no credible public proof of concept. Neither point proves that exploitation has not occurred, and defenders should not use the absence of public activity as a reason to delay.

What administrators should do now

First, inventory each Firebox by model, exact running version and role. Do not apply the headline version to every device without checking the correct branch. The fixed releases are:

  • Fireware OS 2026.3.2 for the 2026.3 branch.
  • Fireware OS 2026.2.3 for the 2025.0 through 2026.2 branch.
  • Fireware OS 12.12.3 for the general 12.x branch.
  • Fireware OS 12.5.21 for affected T15 and T35 appliances.
  • Fireware OS 12.11.10 for affected EUCC systems covered by the SAML session-file advisory.

After upgrading, confirm the running version after reboot rather than relying only on a completed update job. In high-availability pairs, verify both members and check that traffic has returned to the intended active appliance.

Organisations using BOVPN over TLS should identify every Firebox operating as a client, confirm who controls the remote server and compare its identity and configuration with the expected deployment record. Unexpected server changes, newly introduced configuration, unexplained root-level activity or unplanned tunnel changes deserve investigation.

Reduce exposure while patching. Limit management and Access Portal reachability to the networks and users that need it. Review read-only, guest and low-privilege accounts rather than assuming they cannot affect availability or retrieve sensitive files. On local networks, treat unexpected DHCP activity and repeated fingerprinting-daemon failures as signals worth investigating.

Operational logs should also be checked for unusual wgagent, iked, spamd, samld or NetFlow crashes. Those events are not proof of exploitation by themselves, but they can help identify appliances that need closer review.

This is a new Fireware release, not the old incident

BlackTree previously covered three different Firebox vulnerabilities that could turn a VPN handshake into remote code execution and an older Firebox flaw later linked to ransomware. Most advisories in this separate 15-flaw set were published on 29 September UTC, with the latest record appearing at 05:38 CEST on 30 September. It needs its own remediation decision.

The central lesson is not that every Firebox is open to anyone on the internet. It is that infrastructure can be compromised through the systems it has been configured to trust. Patching closes the known code paths. Verifying those trusted relationships is what addresses the larger failure mode.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *