CVE-2026-86104: Fireware OS Resource Exhaustion in Login Process Allows Denial of Service
An uncontrolled resource consumption vulnerability in the Fireware OS login process (wgagent) allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted request.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fireware OSto a version that resolves this vulnerability.Fixed in 2026.3.2 - Upgrade
Upgrade
Fireware OSto a version that resolves this vulnerability.Fixed in 2026.2.3 - Upgrade
Upgrade
Fireware OSto a version that resolves this vulnerability.Fixed in 12.12.3 - Upgrade
Upgrade
Fireware OSto a version that resolves this vulnerability.Fixed in 12.5.21
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote, unauthenticated attacker can exploit the issue by sending a specially crafted request to the affected Fireware OS login process, wgagent.
What is the expected impact of a successful attack?
Successful exploitation can exhaust resources in the login process and cause a denial of service.