CVE-2026-86131
Received
Received - Intake
Code Injection in WatchGuard Fireware OS via BOVPN Over TLS
Vulnerability report for CVE-2026-86131, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-30
Last updated on: 2026-09-30
Assigner: WatchGuard Technologies, Inc.
Description
Description
A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| watchguard | fireware_os | From 2026.3 (inc) to 2026.3.2 (inc) |
| watchguard | fireware_os | From 2025.0 (inc) to 2026.2.3 (inc) |
| watchguard | fireware_os | From 12.0 (inc) to 12.12.3 (inc) |
| watchguard | fireware_os | From 12.0 (inc) to 12.5.21 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-94 | The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment. |
| CWE-829 | The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere. |
| CWE-295 | The product does not validate, or incorrectly validates, a certificate. |