← Back to Feed CACHED · 2026-10-01 18:55:54 · CACHE_KEY CVE-2026-86134
CVE-2026-86134 · CWE-476 · Disclosed 2026-09-30

A NULL pointer dereference vulnerability in the WatchGuard Fireware OS authentication process

ASSESSED — NOISGATE
Vendor
—
—
—
Reassessed
—
—
—
Verdict: —
Do you agree?
01 · The Real Story

Someone can ring your firewall's doorbell until the butler passes out, but the locks on every door stay engaged

CVE-2026-86134 is a NULL pointer dereference in the WatchGuard Fireware OS management daemon's authentication handler. A remote, unauthenticated attacker who can reach the management login interface (TCP/8080 by default) can send a single malformed request that crashes the management daemon, producing a denial-of-service condition. The bug spans a wide version range: Fireware OS 12.0 through 12.12.2, 12.5.x through 12.5.20 (T15/T35 platforms), 2025.0 through 2026.2.2, and 2026.3.0–2026.3.1. Fixed releases are 12.12.3, 12.5.21, 2026.2.3, and 2026.3.2.

Third-party CVSS 4.0 calculators and the WatchGuard PSIRT page assign an 8.7 HIGH, which is the mathematically correct output for an unauthenticated, zero-complexity, high-availability-impact vector. But CVSS does not discount for default-off attack surface or management-plane-only blast radius. The management daemon crash does not interrupt the data-plane forwarding engine — the firewall continues enforcing policy while the admin UI is down. By default, WatchGuard does not expose the management interface to the internet. The combination of DoS-only impact, management-plane-only scope, and default-off exposure means the 8.7 label overstates real-world risk by roughly three points for the vast majority of deployments.

"Pre-auth mgmt-plane DoS on a perimeter device that is not internet-exposed by default"
02 · The Attack Path

4 steps from start to impact.

STEP 01

Locate exposed management interface

The attacker scans for WatchGuard Firebox management interfaces on TCP/8080 or TCP/4117. Historically, Shadowserver and Shodan have indexed tens of thousands of Fireboxes with management ports reachable from the internet, though the default configuration blocks external management access.
Conditions required:
  • Target Firebox management interface is network-reachable to the attacker
Where this breaks in practice:
  • WatchGuard default config blocks external management access via the Any-External alias
  • Best-practice deployments restrict management to a dedicated admin VLAN or VPN-only access
  • Shodan/Censys exposure counts include devices behind ISP NAT or with ACLs that still block unauthenticated probes
Detection/coverage: Shodan dork http.title:"WatchGuard" port:8080 identifies candidates. Fireware access logs record connection attempts to the management port.
STEP 02

Send crafted authentication request

The attacker sends a single specially crafted HTTP request to the Fireware login endpoint. No valid credentials, session tokens, or prior interaction are needed. The malformed input triggers a NULL pointer dereference in the authentication parsing code.
Conditions required:
  • TCP connectivity to the management port
  • Knowledge of the malformed payload structure (no public PoC exists as of 2026-10-02)
Where this breaks in practice:
  • No public proof-of-concept or exploit code has been identified on GitHub, ExploitDB, pocindex.io, or Nuclei templates
  • Developing the payload requires reverse-engineering the management daemon binary or fuzzing the login endpoint
  • WatchGuard's proprietary protocol specifics are not widely documented
Detection/coverage: WAF or reverse-proxy in front of the management UI could log anomalous POST bodies. Fireware system event logs may capture the daemon crash and restart.
STEP 03

Management daemon crashes

The NULL dereference causes the management daemon process to crash. The Fireware Web UI and WatchGuard System Manager connections become unresponsive. The data-plane packet forwarding engine is a separate process and continues enforcing firewall rules normally.
Conditions required:
  • Successful delivery of the crafted request
Where this breaks in practice:
  • Fireware's watchdog process typically restarts crashed daemons within seconds to a few minutes
  • The outage window is brief per crash — sustained DoS requires repeated exploitation
  • Data-plane security policy enforcement is unaffected
Detection/coverage: SNMP traps, syslog forwarding, or WatchGuard Dimension/Cloud Visibility can alert on management daemon restarts. Absence of heartbeat from the management plane is a detectable signal.
STEP 04

Sustained management-plane denial (optional)

The attacker loops the crafted request to keep crashing the management daemon each time the watchdog restarts it, creating an extended window where administrators cannot log in to manage the device. This could be paired with a concurrent attack to deny defenders visibility and control.
Conditions required:
  • Persistent network access to the management port
  • Willingness to generate noisy, repetitive traffic
Where this breaks in practice:
  • Repeated crashes generate high-volume syslog/SNMP alerts that are trivially detectable
  • Network-level rate limiting or IP blocking at the management interface stops the loop
  • The firewall's security posture (ACLs, IPS, VPN) remains intact throughout
Detection/coverage: Any SIEM or NMS monitoring the Firebox will fire on repeated daemon restarts. GreyNoise or similar sensors would flag sustained probing of port 8080.
03 · Compensating Control

1
MEDIUM 5.5→LOW 2.5
SEVERITY REDUCED
Restrict management interface access to trusted source IPs only — Configure the Firebox management access policy to allow TCP/8080 and TCP/4117 only from a dedicated admin VLAN, jump host, or named IP list. This eliminates the unauthenticated remote attack vector entirely. No noisgate mitigation SLA applies for MEDIUM — go straight to the 365-day remediation window, but this control is low-effort and should be validated immediately as hygiene.
2
MEDIUM 5.5→LOW 2.0
SEVERITY REDUCED
Place management behind VPN-only access — Require administrators to establish a VPN tunnel (IPSec or SSLVPN) before reaching the management interface. This adds an authentication gate that the CVE's pre-auth attack path cannot bypass. Deploy within the normal change window.
3
MEDIUM 5.5→MEDIUM 5.0
Enable SNMP/syslog monitoring for management daemon restarts — Configure the Firebox to send SNMP traps or syslog events to your SIEM on daemon crash/restart events. This does not prevent exploitation but ensures you detect it within minutes and can block the source IP. Pair with automated IP blocking at the network edge.
4
MEDIUM 5.5→IGNORE 0.0
SEVERITY REDUCED
Apply vendor patch (Fireware 2026.3.2 / 2026.2.3 / 12.12.3 / 12.5.21) — The definitive fix. Schedule within the noisgate remediation SLA of 365 days for MEDIUM severity. Given the low exploitation risk, this can follow your standard firewall maintenance window cadence.
What doesn't work
  • WAF in front of the Firebox — the management interface is a native service on the Firebox itself, not a backend web application. Inserting a WAF between the internet and the firewall's management port is architecturally impractical and would break management workflows.
  • IPS signatures on the Firebox itself — the Firebox's IPS engine inspects transit traffic through the firewall, not traffic destined to the firewall's own management services. A crafted request to TCP/8080 is processed by the management daemon before IPS ever sees it.
  • Rate limiting alone — while rate limiting slows sustained DoS loops, a single crafted packet is sufficient to crash the daemon once. Rate limiting reduces impact duration but does not prevent the initial crash.
04 · Intelligence Metadata

The supporting signals.

In-the-wild exploitationNone observed. WatchGuard PSIRT states they are "not aware of any exploitation of this vulnerability in the wild." Not listed in CISA KEV. No GreyNoise tags or campaigns as of 2026-10-02.
Proof-of-concept availabilityNo public PoC found. Checked pocindex.io, GitHub (no repos named CVE-2026-86134), ExploitDB, Nuclei templates, and Metasploit modules. The exploit requires reverse-engineering the proprietary management daemon.
EPSS score0.00422 — bottom ~15th percentile. Reflects very low predicted exploitation probability in the next 30 days.
KEV statusNot listed in the CISA Known Exploited Vulnerabilities catalog as of 2026-10-02.
CVSS vectorCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N — 8.7 HIGH (CVSS 4.0). Equivalent CVSS 3.1 vector would score ~7.5. High score driven entirely by availability impact with zero-friction access; no confidentiality or integrity impact.
Affected versionsFireware OS ≥12.0, <12.12.3 (default platforms); ≥12.0, <12.5.21 (T15/T35); ≥2025.0, <2026.2.3; ≥2026.3.0, <2026.3.2
Fixed versionsFireware OS 2026.3.2, 2026.2.3, 12.12.3, 12.5.21
Internet exposureWatchGuard management interface (TCP/8080, TCP/4117) is not exposed by default. Historical Shadowserver scans have found ~54,000–124,000 Fireboxes with *some* port exposed, but management-interface-specific exposure is a subset driven by misconfiguration. WatchGuard guidance explicitly warns against exposing TCP/8080 via the Any-External alias.
Disclosure date2026-09-30 — published on WatchGuard PSIRT. Two days old at time of assessment.
CreditCredited to WatchGuard AI Security Researchfinder (internal discovery). No external researcher attribution.

Sources.

  1. WatchGuard PSIRT Advisory — CVE-2026-86134
  2. VulDB — CVE-2026-86134 WatchGuard Fireware Authentication Process
  3. Vulners — CVE-2026-86134
  4. Strix AI — CVE-2026-86134 Analysis
  5. INCIBE-CERT — CVE-2026-86134
  6. BleepingComputer — WatchGuard Fireboxes Vulnerable (exposure context)
  7. WatchGuard WGSA-2026-00024 — Related iked Advisory
  8. Threat Radar — CVE-2026-86134 Intelligence
05 · The Call

Final Verdict
↓ DOWNGRADED to MEDIUM (5.5/10)

Why this verdict

  • Impact ceiling is DoS-only. The NULL pointer dereference crashes the management daemon — there is zero path to code execution, data exfiltration, or integrity compromise. The CVSS vector explicitly shows VC:N/VI:N. For a 10,000-host fleet, a temporary management outage on one perimeter device is an inconvenience, not a breach.
  • Default configuration does not expose the attack surface. WatchGuard ships Fireboxes with external management access disabled. The attacker must reach TCP/8080 or TCP/4117, which requires either (a) the admin misconfigured the external access policy, or (b) the attacker is already on the internal/management network — which implies post-initial-access positioning. This compounding prerequisite narrows the reachable population to the misconfigured subset.
  • Data plane continues enforcing policy. The management daemon and the packet-forwarding engine are separate processes. Crashing the management daemon does not cause the firewall to fail open, does not disable IPS/IDS, and does not drop VPN tunnels that are already established. Security posture is maintained throughout the DoS window.
  • No PoC, no exploitation, bottom-percentile EPSS. With an EPSS of 0.00422, no public exploit code, and no observed campaigns, the near-term weaponization risk is very low. The proprietary nature of the management daemon raises the bar for independent exploit development.
  • Watchdog auto-restart limits blast duration. Fireware's process watchdog restarts crashed daemons within seconds. Sustained DoS requires the attacker to maintain a persistent loop of crafted requests, which is noisy and trivially blocked at the network level.
  • Role multiplier: WatchGuard Firebox is a *network edge appliance* and sits in the high-value-role catalog. However, the documented chain's outcome is *management-plane DoS*, NOT domain takeover, fleet compromise, mass data egress, supply-chain pivot, or OT-safety impact. The data-plane security function remains intact. Therefore, the high-value-role floor (HIGH for ≥1% installed base with catastrophic outcome) does not activate. The Firebox continues to protect the network even while its admin UI is crashed.

Why not higher?

Promoting to HIGH would require either a path to code execution, a data-plane impact, or evidence of active exploitation — none of which exist. The management daemon crash is a recoverable, auto-restarting availability event that does not degrade the firewall's security enforcement. The default-off internet exposure further narrows the reachable population. While WatchGuard is a perimeter device, the attack outcome (temporary loss of management UI) does not meet the catastrophic-outcome threshold that would invoke the high-value-role floor.

Why not lower?

Dropping to LOW would underweight the fact that the attack is pre-authentication, zero-complexity, and targets a security-critical appliance class. In the misconfigured-but-real subset of deployments where management is internet-facing, this is a single-packet DoS with no prerequisites. The potential for an attacker to blind defenders during a concurrent intrusion by repeatedly crashing the management plane is a meaningful operational risk that keeps this in MEDIUM territory.

06 · Verification

Crowdsourced verification payload.

Run this script from an auditor workstation with SSH access to the target Firebox. Usage: bash check_cve_2026_86134.sh 10.0.1.1 admin — requires read-only admin SSH credentials. The script retrieves the installed Fireware version and checks it against known-vulnerable ranges.

noisgate-verify.sh
BASHREAD-ONLYSAFE
#!/usr/bin/env bash
# CVE-2026-86134 — WatchGuard Fireware OS NULL Pointer Dereference version check
# Outputs: VULNERABLE / PATCHED / UNKNOWN
# Exit codes: 1=VULNERABLE, 0=PATCHED, 2=UNKNOWN

set -uo pipefail

HOST="${1:?Usage: $0 <FIREBOX_MGMT_IP> [SSH_USER]}"
USER="${2:-admin}"

# Retrieve Fireware version via SSH
RAW=$(ssh -o StrictHostKeyChecking=no -o ConnectTimeout=10 "${USER}@${HOST}" "show sysinfo" 2>/dev/null)
if [[ $? -ne 0 || -z "$RAW" ]]; then
    echo "UNKNOWN — could not retrieve Fireware version from ${HOST} via SSH"
    exit 2
fi

VERSION=$(echo "$RAW" | grep -iE 'firmware|version' | head -1 | grep -oP '[0-9]+\.[0-9]+(\.[0-9]+)*' | head -1)
if [[ -z "$VERSION" ]]; then
    echo "UNKNOWN — could not parse Fireware version from sysinfo output"
    exit 2
fi

echo "Detected Fireware version: ${VERSION}"

IFS='.' read -ra V <<< "$VERSION"
MAJOR="${V[0]:-0}"
MINOR="${V[1]:-0}"
PATCH="${V[2]:-0}"

VULNERABLE=0

if (( MAJOR == 2026 )); then
    if (( MINOR == 3 )); then
        (( PATCH < 2 )) && VULNERABLE=1
    elif (( MINOR == 2 )); then
        (( PATCH < 3 )) && VULNERABLE=1
    elif (( MINOR < 2 )); then
        VULNERABLE=1
    fi
elif (( MAJOR == 2025 )); then
    VULNERABLE=1
elif (( MAJOR == 12 )); then
    if (( MINOR == 12 )); then
        (( PATCH < 3 )) && VULNERABLE=1
    elif (( MINOR == 5 )); then
        (( PATCH < 21 )) && VULNERABLE=1
    elif (( MINOR > 5 && MINOR < 12 )); then
        VULNERABLE=1
    elif (( MINOR < 5 && MINOR >= 0 )); then
        VULNERABLE=1
    fi
fi

if (( VULNERABLE == 1 )); then
    echo "VULNERABLE — Fireware ${VERSION} is affected by CVE-2026-86134"
    exit 1
else
    echo "PATCHED — Fireware ${VERSION} is not affected by CVE-2026-86134"
    exit 0
fi
Peer Review

What defenders are saying.

Submit a review attribution: handle + country only
0 flags selected · stored anonymously