CVE-2026-86104 PUBLISHED

Fireware OS Resource Exhaustion in Login Process Allows Denial of Service

Assigner: WatchGuard
Reserved: 05.09.2026 Published: 29.09.2026 Updated: 30.09.2026

An uncontrolled resource consumption vulnerability in the Fireware OS login process (wgagent) allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted request.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor WatchGuard
Product Fireware OS
Versions Default: unaffected
  • affected from 2026.3 to 2026.3.2 (excl.)
  • affected from 2025.0 to 2026.2.3 (excl.)
  • affected from 12.0 to 12.12.3 (excl.)
Vendor WatchGuard
Product Fireware OS
Versions Default: unaffected
  • affected from 12.0 to 12.5.21 (excl.)

Affected Configurations

To exploit this vulnerability, an attacker needs access to an authentication interface such as the management Web UI or the Access Portal.

Exploits

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solutions

Fireware OS 2026.3.2, Fireware OS 2026.2.3, Fireware OS 12.12.3, Fireware OS 12.5.21

Credits

  • WatchGuard AI Security Research finder
  • Laurent GAFFIE , secorizon.com finder

References

Problem Types

  • CWE-400 CWE
  • CWE-409 CWE
  • CWE-770 CWE