Vulnerabilities · 2h ago

WatchGuard Fireware Trusts the Wrong VPN Peer

INCIBE-CERT said WatchGuard Fireware OS has a critical remote code execution flaw, CVE-2026-86131, in the way it handles BOVPN over TLS client configuration. On affected Firebox T15 and T35 systems, and other Fireware OS releases listed by WatchGuard, a malicious remote VPN server can send a crafted configuration and make the appliance run root commands. WatchGuard says it has no evidence of exploitation.

The weakness sits in the trust exchange at tunnel setup: the Firebox accepts configuration data from the remote BOVPN peer, so a server the operator chose to connect to can turn that relationship into appliance compromise. In plain terms, the danger is not just the VPN session; it is the control plane of the firewall itself.

For shops that build site-to-site tunnels to third-party or otherwise untrusted VPN endpoints, the exposure follows the connection partner, not only the firewall's perimeter. Once that peer is malicious or compromised, whatever sits behind the Firebox inherits the blast radius of a rooted appliance.

CVE-2026-101891

NVD KEV

CVE-2026-86102

NVD KEV

Timeline

Sources

2 sources covering this story

Entities

Part of the PlainSec briefing for 2026-09-30

Editions

Related stories