Description
A NULL pointer dereference vulnerability in the WatchGuard Fireware OS authentication process allows a remote, unauthenticated attacker to crash the management daemon by sending a specially request to the login interface, resulting in a denial of service.
Published: 2026-09-30
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Denial of Service
Action: Apply Patch
AI Analysis

Impact

A NULL pointer dereference flaw in the authentication process of WatchGuard Fireware OS allows an unauthenticated remote attacker to crash the management daemon by sending a specially crafted request to the login interface. This causes a denial of service that interrupts remote management sessions. The underlying weakness is a null pointer dereference (CWE‑476), which leads the software to attempt to access uninitialized memory and crash.

Affected Systems

The vulnerability affects WatchGuard Fireware OS devices running any of the following versions: 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21. Devices running earlier releases that have not applied the listed updates are vulnerable.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity impact on availability, while the EPSS score is not available and the flaw is not listed in the CISA KEV catalog. The likely attack path involves an unauthenticated remote attacker sending a crafted packet to the management daemon’s login endpoint; no authentication is required, and the exploit can be performed from any network that can reach the device. If successful, the daemon will crash, causing a temporary loss of remote management functionality until a restart occurs.

Generated by OpenCVE AI on September 30, 2026 at 07:14 UTC.

Remediation

Vendor Solution

Fireware OS 2026.3.2, Fireware OS 2026.2.3, Fireware OS 12.12.3, Fireware OS 12.5.21


OpenCVE Recommended Actions

  • Upgrade the device to WatchGuard Fireware OS 2026.3.2, 2026.2.3, 12.12.3, or 12.5.21 if it is not already at one of these releases.
  • Restrict access to the login interface by applying firewall rules or network segmentation so that only trusted network segments can reach the management daemon.
  • Monitor system logs for repeated crashes of the management daemon and apply a temporary restart script to maintain availability until a patch can be deployed.

Generated by OpenCVE AI on September 30, 2026 at 07:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Description A NULL pointer dereference vulnerability in the WatchGuard Fireware OS authentication process allows a remote, unauthenticated attacker to crash the management daemon by sending a specially request to the login interface, resulting in a denial of service.
Title Fireware OS Pre-Authentication NULL Pointer Dereference Allows Remote Denial of Service
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-476
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:*
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Watchguard Fireware Os
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-09-30T14:38:30.274Z

Reserved: 2026-09-05T03:10:50.777Z

Link: CVE-2026-86134

cve-icon Vulnrichment

Updated: 2026-09-30T14:38:27.156Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T04:18:33.337

Modified: 2026-09-30T16:40:50.560

Link: CVE-2026-86134

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T09:00:07Z

Weaknesses