INCIBE-CERT said WatchGuard Fireware OS has a critical remote code execution flaw, CVE-2026-86131, in the way it handles BOVPN over TLS client configuration. On affected Firebox T15 and T35 systems, and other Fireware OS releases listed by WatchGuard, a malicious remote VPN server can send a crafted configuration and make the appliance run root commands. WatchGuard says it has no evidence of exploitation.
The weakness sits in the trust exchange at tunnel setup: the Firebox accepts configuration data from the remote BOVPN peer, so a server the operator chose to connect to can turn that relationship into appliance compromise. In plain terms, the danger is not just the VPN session; it is the control plane of the firewall itself.
For shops that build site-to-site tunnels to third-party or otherwise untrusted VPN endpoints, the exposure follows the connection partner, not only the firewall's perimeter. Once that peer is malicious or compromised, whatever sits behind the Firebox inherits the blast radius of a rooted appliance.
WatchGuard ha rilasciato aggiornamenti di sicurezza per risolvere molteplici vulnerabilità, di cui 1 con gravità "critica" e 13 con gravità "alta", presenti in Fireware OS, sistema operativo utilizzato nei dispositivi di sicurezza perimetrale e di protezione delle reti.
Aggiornamenti di sicurezza WatchGuard sanano 3 vulnerabilità, 2 con gravità “critica” e una con gravità “alta”, in WatchGuard AP, dispositivi di accesso wireless utilizzati per la connettività e la gestione delle reti Wi-Fi.