CVE-2026-86131: Fireware OS Code Injection in BOVPN Over TLS Client Allows Remote Code Execution
A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 2026.3.2 - Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 2026.2.3 - Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 12.12.3 - Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 12.5.21
Event History
Frequently Asked Questions
What position must an attacker have to exploit this issue?
The attacker must control the remote VPN server used by the BOVPN Over TLS connection. The vulnerable Firebox is the one connecting to that server.
What level of access could successful exploitation provide?
Successful exploitation allows arbitrary commands to be executed as root on the connecting Firebox.