INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

WatchGuard Fixes Critical Fireware OS Flaw for Remote Code Execution

| 2026-09-30 13:16 CRITICAL MEDIUM VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
WatchGuard has released security updates for Fireware OS that address 15 vulnerabilities, including a critical code injection flaw (CVE-2026-86131) tracked as CVSS score of 9.2, allowing an attacker to execute commands with root privileges on a vulnerable Firebox. The flaws include remote code execution, authorization bypass, denial-of-service conditions, unauthorized SSLVPN access and arbitrary file reads. ShinyHunters, an APT group, is believed to be behind the attack. WatchGuard has patched these vulnerabilities in versions 2026.3.2, 2026.2.3, 12.12.3 and 12.5.21 of Fireware OS. This incident highlights the importance of regular software updates and patching to prevent such attacks.
Technical Mitigations AI-generated
• Implement a network segmentation strategy to limit the attack surface of Firebox appliances, reducing the potential impact of an attacker controlling the remote VPN server. • Configure BOVPN over TLS clients with strict access controls and authentication mechanisms to prevent unauthorized access and code injection vulnerabilities. • Regularly update Fireware OS to version 2026.3.2 or later, as well as other affected branches, to patch known vulnerabilities and reduce the risk of exploitation.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters CVE-2026-86131CVE-2026-86131 CVE-2026-81433CVE-2026-81433 CVE-2026-101891CVE-2026-101891 CVE-2026-86102CVE-2026-86102 CVE-2026-86101CVE-2026-86101
Target & Sectors
Global Scope
Incident Timeline
‎2026.2.3
WatchGuard addressed the CVE-2026-86131 code injection vulnerability in Fireware OS versions 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21 starting with version 2026.3.2 on ‎2026.2.3.
infrastructure 2026.3.2
infrastructure 2026.2.3
infrastructure 12.12.3
infrastructure 12.5.21
vulnerability CVE-2026-86131
‎September 29
WatchGuard has released security updates for its Fireware OS on September 29 to address a critical code injection vulnerability.
‎September 30, 2026
WatchGuard patches a critical Fireware OS code injection vulnerability, allowing remote code execution.
tactic Remote Code Execution
‎2026/09/30
WatchGuard has released security updates for Fireware OS that address 15 vulnerabilities, including a critical code injection flaw tracked as CVE-2026-86131 with a CVSS score of 9.2.
threat_actor ShinyHunters
organisation PeopleSoft
organisation Zero-Click Data Exfiltration
organisation WatchGuard
organisation Fireware
organisation CVE-2026-86131
infrastructure 9.2
organisation Firebox
organisation TLS
organisation WatchGuard Firebox
organisation Access Point
organisation CVE-2026
organisation API
infrastructure 3.4.8
organisation WatchGuard AP
organisation RCE
organisation DoS
organisation DHCP
organisation CVE-2026-81433
organisation WatchGuard Fireware OS’s
organisation IPsec
organisation SSL
organisation SecurityAffairs
Tactical Metrics
Metrics
infrastructure
‎2026.3.2
Software Version
Metrics
infrastructure
‎2026.2.3
Software Version
Metrics
infrastructure
‎12.12.3
Software Version
Metrics
infrastructure
‎12.5.21
Software Version
Metrics
infrastructure
‎3.4.8
Software Version
Metrics
infrastructure
‎9.2
Software Version
Intelligence Sources