Full Report
WatchGuard security advisory (AV26-981)
Analysis Summary
# Vulnerability: WatchGuard Fireware OS Pre-Authentication Denial of Service
## CVE Details
- **CVE ID:** CVE-2026-86134
- **CVSS Score:** 7.5 (High)
- **CWE:** CWE-476 (NULL Pointer Dereference)
## Affected Systems
- **Products:** WatchGuard Fireware OS
- **Versions:**
- Versions prior to 12.12.3
- Versions prior to 12.5.21
- Versions prior to 2026.2.3
- Versions prior to 2026.3.2
- **Configurations:** Systems running the affected OS versions with exposed management or network interfaces.
## Vulnerability Description
A NULL pointer dereference vulnerability exists in the Fireware OS. The flaw occurs during the pre-authentication phase, meaning an attacker does not need valid credentials to trigger the bug. By sending a specially crafted request to the device, an attacker can cause the system to attempt to read a memory location that is NULL, resulting in a system crash or an unplanned reboot of the security appliance.
## Exploitation
- **Status:** Not exploited (Based on current advisory data; no reports of active exploitation in the wild).
- **Complexity:** Low
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** None
- **Integrity:** None
- **Availability:** High (Complete Denial of Service for the firewall and protected network).
## Remediation
### Patches
WatchGuard has released the following firmware versions to address this vulnerability. Administrators should upgrade to the relevant branch for their hardware:
- **Fireware OS 12.12.3** or later
- **Fireware OS 12.5.21** or later
- **Fireware OS 2026.2.3** or later
- **Fireware OS 2026.3.2** or later
### Workarounds
- **Access Control:** Restrict access to the Fireware management web interface (WebUI) and SNMP to trusted internal IP addresses only.
- **External Exposure:** Ensure that management interfaces are not exposed to the public internet.
## Detection
- **Indicators of Compromise:** Unexpected and repeated reboots of the WatchGuard appliance without a clear hardware cause.
- **Detection methods and tools:** Review system logs for crashes occurring during the pre-authentication phase of network connections. Monitor device uptime via SNMP or WatchGuard Cloud.
## References
- WatchGuard PSIRT Advisory: hxxps[://]psirt[.]watchguard[.]com/CVE-2026-86134
- WatchGuard Security Advisories: hxxps[://]psirt[.]watchguard[.]com/
- Canadian Centre for Cyber Security (AV26-981): hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/watchguard-security-advisory-av26-981