Skip to content
TrustList
News

WatchGuard fixes a critical Fireware OS flaw and two critical access-point flaws: update to Fireware 2026.3.2 and AP firmware 3.4.8

Editorial

By TrustList Editorial

WatchGuard published fixes on 29 September 2026 for a critical Fireware OS code-injection flaw (CVSS 9.2) and many others, plus two critical WatchGuard AP flaws (CVSS 9.3). WatchGuard says it knows of no exploitation.

About WatchGuard fixes a critical Fireware OS flaw and two critical access-point flaws: update to Fireware 2026.3.2 and AP firmware 3.4.8

WatchGuard fixes a critical Fireware OS flaw and two critical access-point flaws: update to Fireware 2026.3.2 and AP firmware 3.4.8

29 September 2026 — WatchGuard's product security team published a batch of advisories dated 29 September 2026 for Fireware OS, the operating system of its Firebox firewalls, and separate advisories for its WatchGuard AP wireless access points. For both, WatchGuard says it "is not aware of any exploitation of this vulnerability in the wild".

Fireware OS: a critical flaw in the BOVPN-over-TLS client

The most serious Fireware issue is CVE-2026-86131, "Code Injection in BOVPN Over TLS Client Allows Remote Code Execution", rated critical at 9.2 under CVSS v4.0. It affects Fireboxes using the branch-office VPN over TLS client. The advisory list carries a series of further Fireware OS fixes on the same date, among them CVE-2026-86136, a missing authorisation check in the wgagent management API that allows denial of service.

Fixed versions, by release line:

  • 2026.3.2 (for 2026.3 before 2026.3.2);
  • 2026.2.3 (for 2025.0 up to 2026.2.3);
  • 12.12.3 (for 12.0 up to 12.12.3);
  • 12.5.21 on T15 and T35 models;
  • 12.11.10 on EUCC-certified builds, for the advisories that list them.

WatchGuard AP: unauthenticated API access and command injection

Two access-point flaws are rated critical at 9.3 under CVSS v4.0:

  • CVE-2026-101891: an internal API service lets "an unauthenticated attacker with network access to the AP obtain a valid API session".
  • CVE-2026-86102: OS command injection in the internal management API lets an attacker with network access run arbitrary shell commands.

Both affect WatchGuard AP firmware from 1.0 up to 3.4.8 and are fixed in 3.4.8. A third access-point flaw, a command injection in the diagnostic command line that needs an administrator account, is fixed in the same release.

What to do

  • Upgrade Fireboxes to the fixed Fireware OS release for their line, starting with any that use BOVPN over TLS.
  • Upgrade every WatchGuard AP to firmware 3.4.8. Until then, keep the access points' management interfaces on an isolated management network.
  • Partners managing Fireboxes for clients should schedule the updates across their fleet and confirm versions in WatchGuard Cloud or the management server.

Sources

Categories & features