# WatchGuard Patches Fireware Vulnerabilities

WatchGuard released updates for 15 Fireware OS vulnerabilities, including critical remote code execution flaw CVE-2026-86131 (CVSS 9.2). An attacker controlling a VPN server could use the flaw to execute commands as root on a connected Firebox appliance. WatchGuard said it was not aware of exploitation in the wild. The advisory identifies no government contract or agency procurement action, but it is relevant to contractors that use affected Firebox or WatchGuard Access Point products.

- Organizations using these products should identify affected deployments and apply the updates listed by WatchGuard.
- Procurement and security teams can use the advisory to review whether affected equipment is in their environments and account for patch support in product lifecycle and supplier-risk assessments.

**Jurisdictions:** federal
**Industries:** Information Technology
**Topics:** Cybersecurity
**Published:** September 30, 2026

### Vendors
- WatchGuard ()

### Sources
- [WatchGuard Patches Critical Fireware OS Code Injection Vulnerability - SecurityWeek](https://www.securityweek.com/watchguard-patches-critical-fireware-os-code-injection-vulnerability) - SecurityWeek