CVE-2026-86131

LOWCVSS 9.2 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-295CWE-829

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 1 mentions (2026-09-29); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-09-29: 1Mentions · 2026-09-30: 109-2909-30
Referenced assets2 URLs
Full discourse2 posts
  • Daily CyberSecurity@Daily_CyberSec

    WatchGuard patched 14 Fireware OS vulnerabilities, including CVSS 9.2 RCE flaw CVE-2026-86131 in BOVPN Over TLS. Update Firebox appliances now. #WatchGuard #FirewareOS #Firebox #CVE202686131 #FirewallSecurity #VPN #NetworkSecurity #PatchNow https://securityonline.info/watchguard-fireware-os-vulnerabilities/

    01020297
    13.0K followersView on X
  • CVE@CVEnew

    CVE-2026-86131 A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execu… https://www.cve.org/CVERecord?id=CVE-2026-86131

    00110629
    58.1K followersView on X

Explore more