# WatchGuard Patches 21 Fireware OS Flaws

Published: 2026-10-07 · Severity: elevated
Canonical: https://vorant.io/reports/369b8e86-5c03-5b69-b20d-09780b13a40b/watchguard-patches-21-fireware-os-flaws

> WatchGuard fixed 21 vulnerabilities in Fireware OS, including unauthenticated RCE and DoS bugs in VPN, DHCP and management services, up to CVSS 9.3.

NCSC-NL has published an advisory summarizing 21 vulnerabilities that WatchGuard has patched in Fireware OS, the firmware running on Firebox security appliances, along with related components (WatchGuard Access Points, WatchGuard Dimension). The flaws span a wide range of weakness classes including path traversal, stack-based buffer overflow, code injection, integer underflow, NULL pointer dereference, deserialization of untrusted data, improper authorization and a libxml2 out-of-bounds read. Several of the most serious issues require no authentication and only network access: a stack-based buffer overflow in the DHCP fingerprinting daemon can yield remote code execution or a crash, a NULL pointer dereference in NetFlow packet processing can crash the device remotely, and integer underflow flaws in the IKE/IKEv2 daemons allow unauthenticated denial-of-service. A code-injection vulnerability in the BOVPN Over TLS client configuration lets an attacker who controls the remote VPN server execute commands with root privileges on the Firebox itself — a notable risk for organizations using third-party or less-trusted VPN peers. Other issues require some level of authentication: a malicious SAML SSO session file can lead to arbitrary code execution for an attacker with write access, authenticated admins can read arbitrary files via path traversal in the WebUI Management Agent, and low-privileged authenticated users can escalate access to Mobile VPN with SSL or to unauthorized web applications through flaws in the Access Portal and its reverse proxy.

Additional issues affect WatchGuard Access Points (OS command injection via an internal API) and WatchGuard Dimension (CSRF allowing unauthorized database snapshot creation). CVSS scores range widely, with several in the 8–9.3 band reflecting significant impact (RCE, privileged command execution, file disclosure), though NCSC-NL does not indicate any of the 21 CVEs are being exploited in the wild. WatchGuard has released firmware updates addressing all listed CVEs; defenders running Fireware OS, Firebox appliances, WatchGuard Access Points, or Dimension should prioritize patching, particularly for the unauthenticated network-facing issues (DHCP daemon, NetFlow, IKE/IKEv2) and the VPN-related code injection, and review SAML SSO and Access Portal configurations for unauthorized access indicators.

No indicators of compromise, threat actor attribution, or active exploitation are described in this advisory — it is a vendor patch bulletin relayed by the Dutch national CERT. Defenders should treat this as a patch-management priority rather than an active-incident response action, while still monitoring for anomalous VPN server behavior, unexpected SAML session files, and crashes in DHCP/NetFlow/IKE services as potential exploitation attempts.

## Mentioned in this report

- Vulnerabilities: CVE-2026-13046, CVE-2026-13224, CVE-2026-13225, CVE-2026-18105, CVE-2026-18145, CVE-2026-18146, CVE-2026-81433, CVE-2026-86101, CVE-2026-86102, CVE-2026-86104, CVE-2026-86105, CVE-2026-86106, CVE-2026-86128, CVE-2026-86131, CVE-2026-86132, CVE-2026-86133, CVE-2026-86134, CVE-2026-86135, CVE-2026-86136, CVE-2026-86137, CVE-2026-90441

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0404.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/369b8e86-5c03-5b69-b20d-09780b13a40b/watchguard-patches-21-fireware-os-flaws.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
