Vulnerabilities & Exploits

WatchGuard Fireware Trusts the Wrong VPN Peer

INCIBE-CERT said WatchGuard Fireware OS has a critical remote code execution flaw, CVE-2026-86131, in the way it handles BOVPN over TLS client configuration. On affected Firebox T15 and T35 systems, and other Fireware OS releases listed by WatchGuard, a malicious remote VPN server can send a crafted configuration and make the appliance run root commands. WatchGuard says it has no evidence of exploitation.

The weakness sits in the trust exchange at tunnel setup: the Firebox accepts configuration data from the remote BOVPN peer, so a server the operator chose to connect to can turn that relationship into appliance compromise. In plain terms, the danger is not just the VPN session; it is the control plane of the firewall itself.

For shops that build site-to-site tunnels to third-party or otherwise untrusted VPN endpoints, the exposure follows the connection partner, not only the firewall's perimeter. Once that peer is malicious or compromised, whatever sits behind the Firebox inherits the blast radius of a rooted appliance.

2 sources · 3h ago

CVE-2026-101891

NVD KEV

CVE-2026-86102

NVD KEV

Timeline

Sources

Part of the PlainSec briefing for 2026-09-30

Every edition of this story: WatchGuard Fireware Trusts the Wrong VPN Peer

More from today