CVE-2026-86131
CRITICALCVSS 9.2/10
Last modified
CVE-2026-86131 is a critical-severity vulnerability rated 9.2/10 on the CVSS scale. A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox..
Description
A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| WatchGuard | Fireware OS | >= 2026.3, < 2026.3.2; >= 2025.0, < 2026.2.3; >= 12.0, < 12.12.3 |
| WatchGuard | Fireware OS | >= 12.0, < 12.5.21 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-86131?
A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.
How severe is CVE-2026-86131?
CVE-2026-86131 has a CVSS score of 9.2/10 (CRITICAL severity).
How do I fix CVE-2026-86131?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-86121Cua computer-server versions before 0.3.42 skip authenticati…9.8
- CVE-2026-86122Rowboat through 0.9.1 fails to validate custom MCP server an…5
- CVE-2026-86123SQL Chat contains four unauthenticated API endpoints that ac…8.7
- CVE-2026-86124AutoAgent contains an unauthenticated remote code execution …9.8
- CVE-2026-86128A NULL pointer dereference vulnerability in Fireware OS's Ne…8.2
- CVE-2026-8613The aThemes Addons for Elementor plugin for WordPress is vul…6.4
- CVE-2026-86132An integer underflow vulnerability in the WatchGuard Firewar…8.2
- CVE-2026-86133An integer underflow vulnerability in the WatchGuard Firewar…8.2
- CVE-2026-86135A Cross-Site Request Forgery (CSRF) vulnerability in WatchGu…7
- CVE-2026-86136A missing authorization vulnerability in the wgagent managem…7.1
- CVE-2026-86137In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-…6.1
- CVE-2026-86138In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an…7.8
Are you affected by CVE-2026-86131?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
