CVE-2026-86134: Fireware OS Pre-Authentication NULL Pointer Dereference Allows Remote Denial of Service
Published Sep 30, 2026
·Updated
A NULL pointer dereference vulnerability in the WatchGuard Fireware OS authentication process allows a remote, unauthenticated attacker to crash the management daemon by sending a specially request to the login interface, resulting in a denial of service.
Affected Software
1 affected component
WatchGuard Fireware OS
Event History
Sep 30, 2026
CVE Published
via MITRE·03:37 AM
Data Sourced
via MITRE·03:37 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·04:18 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does an attacker need valid credentials to exploit this issue?
No. The vulnerability can be triggered by a remote, unauthenticated attacker that can send a specially crafted request to the login interface.