CVE-2026-86131
CVE-2026-86131: 1 tracked advisory record across WatchGuard. Compare source-reported impact, fixes and remediation.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
WatchGuard
1 advisory- Advisory severityCritical9.2
Critical [CVE-2026-86131] code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox
CVE-2026-86131Source published Source updated
A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.
- Affected products in this advisory
- Fireware OS
- Source-reported affected versions
- Fireware OS 2026.3 before 2026.3.2
- Fireware OS 2025.0 before 2026.2.3
- Fireware OS 12.0 before 12.12.3
- Fireware OS 12.0 before 12.5.21
- Source-reported fixed versions
- 2026.3.2
- 2026.2.3
- 12.12.3
- 12.5.21
- Mitigation guidance
- No mitigation guidance extracted; consult the source.
Android app · Google Play
Monitor future WatchGuard CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.