CVE-2026-86134 PUBLISHED

Fireware OS Pre-Authentication NULL Pointer Dereference Allows Remote Denial of Service

Assigner: WatchGuard
Reserved: 05.09.2026 Published: 30.09.2026 Updated: 30.09.2026

A NULL pointer dereference vulnerability in the WatchGuard Fireware OS authentication process allows a remote, unauthenticated attacker to crash the management daemon by sending a specially request to the login interface, resulting in a denial of service.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor WatchGuard
Product Fireware OS
Versions Default: unaffected
  • affected from 2026.3 to 2026.3.2 (excl.)
  • affected from 2025.0 to 2026.2.3 (excl.)
  • affected from 12.0 to 12.12.3 (excl.)
Vendor WatchGuard
Product Fireware OS
Versions Default: unaffected
  • affected from 12.0 to 12.5.21 (excl.)

Exploits

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solutions

Fireware OS 2026.3.2, Fireware OS 2026.2.3, Fireware OS 12.12.3, Fireware OS 12.5.21

Credits

  • WatchGuard AI Security Research finder

References

Problem Types

  • CWE-476 CWE