WatchGuard fixes a critical Fireware OS flaw and two critical access-point flaws: update to Fireware 2026.3.2 and AP firmware 3.4.8
EditorialBy TrustList Editorial
WatchGuard published fixes on 29 September 2026 for a critical Fireware OS code-injection flaw (CVSS 9.2) and many others, plus two critical WatchGuard AP flaws (CVSS 9.3). WatchGuard says it knows of no exploitation.
- United States
- Seattle, Wa
- Cybersecurity
- Firewalls
- +2 more
About WatchGuard fixes a critical Fireware OS flaw and two critical access-point flaws: update to Fireware 2026.3.2 and AP firmware 3.4.8
WatchGuard fixes a critical Fireware OS flaw and two critical access-point flaws: update to Fireware 2026.3.2 and AP firmware 3.4.8
29 September 2026 — WatchGuard's product security team published a batch of advisories dated 29 September 2026 for Fireware OS, the operating system of its Firebox firewalls, and separate advisories for its WatchGuard AP wireless access points. For both, WatchGuard says it "is not aware of any exploitation of this vulnerability in the wild".
Fireware OS: a critical flaw in the BOVPN-over-TLS client
The most serious Fireware issue is CVE-2026-86131, "Code Injection in BOVPN Over TLS Client Allows Remote Code Execution", rated critical at 9.2 under CVSS v4.0. It affects Fireboxes using the branch-office VPN over TLS client. The advisory list carries a series of further Fireware OS fixes on the same date, among them CVE-2026-86136, a missing authorisation check in the wgagent management API that allows denial of service.
Fixed versions, by release line:
- 2026.3.2 (for 2026.3 before 2026.3.2);
- 2026.2.3 (for 2025.0 up to 2026.2.3);
- 12.12.3 (for 12.0 up to 12.12.3);
- 12.5.21 on T15 and T35 models;
- 12.11.10 on EUCC-certified builds, for the advisories that list them.
WatchGuard AP: unauthenticated API access and command injection
Two access-point flaws are rated critical at 9.3 under CVSS v4.0:
- CVE-2026-101891: an internal API service lets "an unauthenticated attacker with network access to the AP obtain a valid API session".
- CVE-2026-86102: OS command injection in the internal management API lets an attacker with network access run arbitrary shell commands.
Both affect WatchGuard AP firmware from 1.0 up to 3.4.8 and are fixed in 3.4.8. A third access-point flaw, a command injection in the diagnostic command line that needs an administrator account, is fixed in the same release.
What to do
- Upgrade Fireboxes to the fixed Fireware OS release for their line, starting with any that use BOVPN over TLS.
- Upgrade every WatchGuard AP to firmware 3.4.8. Until then, keep the access points' management interfaces on an isolated management network.
- Partners managing Fireboxes for clients should schedule the updates across their fleet and confirm versions in WatchGuard Cloud or the management server.
Sources
- WatchGuard PSIRT: security advisories list (advisories dated 29 September 2026) — 29 September 2026
- WatchGuard PSIRT: CVE-2026-86131, Fireware OS code injection in BOVPN over TLS client — 29 September 2026
- WatchGuard PSIRT: CVE-2026-101891, WatchGuard AP improper access control in API service — 28 September 2026
- WatchGuard PSIRT: CVE-2026-86102, WatchGuard AP command injection in internal management API — 28 September 2026
Categories & features
- United States
- Seattle, Wa
- Cybersecurity
- Firewalls
- Network Security
- Patch Management
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More United StatesThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.