Someone can ring your firewall's doorbell until the butler passes out, but the locks on every door stay engaged
CVE-2026-86134 is a NULL pointer dereference in the WatchGuard Fireware OS management daemon's authentication handler. A remote, unauthenticated attacker who can reach the management login interface (TCP/8080 by default) can send a single malformed request that crashes the management daemon, producing a denial-of-service condition. The bug spans a wide version range: Fireware OS 12.0 through 12.12.2, 12.5.x through 12.5.20 (T15/T35 platforms), 2025.0 through 2026.2.2, and 2026.3.0–2026.3.1. Fixed releases are 12.12.3, 12.5.21, 2026.2.3, and 2026.3.2.
Third-party CVSS 4.0 calculators and the WatchGuard PSIRT page assign an 8.7 HIGH, which is the mathematically correct output for an unauthenticated, zero-complexity, high-availability-impact vector. But CVSS does not discount for default-off attack surface or management-plane-only blast radius. The management daemon crash does not interrupt the data-plane forwarding engine — the firewall continues enforcing policy while the admin UI is down. By default, WatchGuard does not expose the management interface to the internet. The combination of DoS-only impact, management-plane-only scope, and default-off exposure means the 8.7 label overstates real-world risk by roughly three points for the vast majority of deployments.
4 steps from start to impact.
Locate exposed management interface
- Target Firebox management interface is network-reachable to the attacker
- WatchGuard default config blocks external management access via the Any-External alias
- Best-practice deployments restrict management to a dedicated admin VLAN or VPN-only access
- Shodan/Censys exposure counts include devices behind ISP NAT or with ACLs that still block unauthenticated probes
http.title:"WatchGuard" port:8080 identifies candidates. Fireware access logs record connection attempts to the management port.Send crafted authentication request
- TCP connectivity to the management port
- Knowledge of the malformed payload structure (no public PoC exists as of 2026-10-02)
- No public proof-of-concept or exploit code has been identified on GitHub, ExploitDB, pocindex.io, or Nuclei templates
- Developing the payload requires reverse-engineering the management daemon binary or fuzzing the login endpoint
- WatchGuard's proprietary protocol specifics are not widely documented
Management daemon crashes
- Successful delivery of the crafted request
- Fireware's watchdog process typically restarts crashed daemons within seconds to a few minutes
- The outage window is brief per crash — sustained DoS requires repeated exploitation
- Data-plane security policy enforcement is unaffected
Sustained management-plane denial (optional)
- Persistent network access to the management port
- Willingness to generate noisy, repetitive traffic
- Repeated crashes generate high-volume syslog/SNMP alerts that are trivially detectable
- Network-level rate limiting or IP blocking at the management interface stops the loop
- The firewall's security posture (ACLs, IPS, VPN) remains intact throughout
- WAF in front of the Firebox — the management interface is a native service on the Firebox itself, not a backend web application. Inserting a WAF between the internet and the firewall's management port is architecturally impractical and would break management workflows.
- IPS signatures on the Firebox itself — the Firebox's IPS engine inspects transit traffic through the firewall, not traffic destined to the firewall's own management services. A crafted request to TCP/8080 is processed by the management daemon before IPS ever sees it.
- Rate limiting alone — while rate limiting slows sustained DoS loops, a single crafted packet is sufficient to crash the daemon once. Rate limiting reduces impact duration but does not prevent the initial crash.
The supporting signals.
| In-the-wild exploitation | None observed. WatchGuard PSIRT states they are "not aware of any exploitation of this vulnerability in the wild." Not listed in CISA KEV. No GreyNoise tags or campaigns as of 2026-10-02. |
|---|---|
| Proof-of-concept availability | No public PoC found. Checked pocindex.io, GitHub (no repos named CVE-2026-86134), ExploitDB, Nuclei templates, and Metasploit modules. The exploit requires reverse-engineering the proprietary management daemon. |
| EPSS score | 0.00422 — bottom ~15th percentile. Reflects very low predicted exploitation probability in the next 30 days. |
| KEV status | Not listed in the CISA Known Exploited Vulnerabilities catalog as of 2026-10-02. |
| CVSS vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N — 8.7 HIGH (CVSS 4.0). Equivalent CVSS 3.1 vector would score ~7.5. High score driven entirely by availability impact with zero-friction access; no confidentiality or integrity impact. |
| Affected versions | Fireware OS ≥12.0, <12.12.3 (default platforms); ≥12.0, <12.5.21 (T15/T35); ≥2025.0, <2026.2.3; ≥2026.3.0, <2026.3.2 |
| Fixed versions | Fireware OS 2026.3.2, 2026.2.3, 12.12.3, 12.5.21 |
| Internet exposure | WatchGuard management interface (TCP/8080, TCP/4117) is not exposed by default. Historical Shadowserver scans have found ~54,000–124,000 Fireboxes with *some* port exposed, but management-interface-specific exposure is a subset driven by misconfiguration. WatchGuard guidance explicitly warns against exposing TCP/8080 via the Any-External alias. |
| Disclosure date | 2026-09-30 — published on WatchGuard PSIRT. Two days old at time of assessment. |
| Credit | Credited to WatchGuard AI Security Researchfinder (internal discovery). No external researcher attribution. |
Sources.
- WatchGuard PSIRT Advisory — CVE-2026-86134
- VulDB — CVE-2026-86134 WatchGuard Fireware Authentication Process
- Vulners — CVE-2026-86134
- Strix AI — CVE-2026-86134 Analysis
- INCIBE-CERT — CVE-2026-86134
- BleepingComputer — WatchGuard Fireboxes Vulnerable (exposure context)
- WatchGuard WGSA-2026-00024 — Related iked Advisory
- Threat Radar — CVE-2026-86134 Intelligence
Why this verdict
- Impact ceiling is DoS-only. The NULL pointer dereference crashes the management daemon — there is zero path to code execution, data exfiltration, or integrity compromise. The CVSS vector explicitly shows VC:N/VI:N. For a 10,000-host fleet, a temporary management outage on one perimeter device is an inconvenience, not a breach.
- Default configuration does not expose the attack surface. WatchGuard ships Fireboxes with external management access disabled. The attacker must reach TCP/8080 or TCP/4117, which requires either (a) the admin misconfigured the external access policy, or (b) the attacker is already on the internal/management network — which implies post-initial-access positioning. This compounding prerequisite narrows the reachable population to the misconfigured subset.
- Data plane continues enforcing policy. The management daemon and the packet-forwarding engine are separate processes. Crashing the management daemon does not cause the firewall to fail open, does not disable IPS/IDS, and does not drop VPN tunnels that are already established. Security posture is maintained throughout the DoS window.
- No PoC, no exploitation, bottom-percentile EPSS. With an EPSS of 0.00422, no public exploit code, and no observed campaigns, the near-term weaponization risk is very low. The proprietary nature of the management daemon raises the bar for independent exploit development.
- Watchdog auto-restart limits blast duration. Fireware's process watchdog restarts crashed daemons within seconds. Sustained DoS requires the attacker to maintain a persistent loop of crafted requests, which is noisy and trivially blocked at the network level.
- Role multiplier: WatchGuard Firebox is a *network edge appliance* and sits in the high-value-role catalog. However, the documented chain's outcome is *management-plane DoS*, NOT domain takeover, fleet compromise, mass data egress, supply-chain pivot, or OT-safety impact. The data-plane security function remains intact. Therefore, the high-value-role floor (HIGH for ≥1% installed base with catastrophic outcome) does not activate. The Firebox continues to protect the network even while its admin UI is crashed.
Why not higher?
Promoting to HIGH would require either a path to code execution, a data-plane impact, or evidence of active exploitation — none of which exist. The management daemon crash is a recoverable, auto-restarting availability event that does not degrade the firewall's security enforcement. The default-off internet exposure further narrows the reachable population. While WatchGuard is a perimeter device, the attack outcome (temporary loss of management UI) does not meet the catastrophic-outcome threshold that would invoke the high-value-role floor.
Why not lower?
Dropping to LOW would underweight the fact that the attack is pre-authentication, zero-complexity, and targets a security-critical appliance class. In the misconfigured-but-real subset of deployments where management is internet-facing, this is a single-packet DoS with no prerequisites. The potential for an attacker to blind defenders during a concurrent intrusion by repeatedly crashing the management plane is a meaningful operational risk that keeps this in MEDIUM territory.
Crowdsourced verification payload.
Run this script from an auditor workstation with SSH access to the target Firebox. Usage: bash check_cve_2026_86134.sh 10.0.1.1 admin — requires read-only admin SSH credentials. The script retrieves the installed Fireware version and checks it against known-vulnerable ranges.
#!/usr/bin/env bash
# CVE-2026-86134 — WatchGuard Fireware OS NULL Pointer Dereference version check
# Outputs: VULNERABLE / PATCHED / UNKNOWN
# Exit codes: 1=VULNERABLE, 0=PATCHED, 2=UNKNOWN
set -uo pipefail
HOST="${1:?Usage: $0 <FIREBOX_MGMT_IP> [SSH_USER]}"
USER="${2:-admin}"
# Retrieve Fireware version via SSH
RAW=$(ssh -o StrictHostKeyChecking=no -o ConnectTimeout=10 "${USER}@${HOST}" "show sysinfo" 2>/dev/null)
if [[ $? -ne 0 || -z "$RAW" ]]; then
echo "UNKNOWN — could not retrieve Fireware version from ${HOST} via SSH"
exit 2
fi
VERSION=$(echo "$RAW" | grep -iE 'firmware|version' | head -1 | grep -oP '[0-9]+\.[0-9]+(\.[0-9]+)*' | head -1)
if [[ -z "$VERSION" ]]; then
echo "UNKNOWN — could not parse Fireware version from sysinfo output"
exit 2
fi
echo "Detected Fireware version: ${VERSION}"
IFS='.' read -ra V <<< "$VERSION"
MAJOR="${V[0]:-0}"
MINOR="${V[1]:-0}"
PATCH="${V[2]:-0}"
VULNERABLE=0
if (( MAJOR == 2026 )); then
if (( MINOR == 3 )); then
(( PATCH < 2 )) && VULNERABLE=1
elif (( MINOR == 2 )); then
(( PATCH < 3 )) && VULNERABLE=1
elif (( MINOR < 2 )); then
VULNERABLE=1
fi
elif (( MAJOR == 2025 )); then
VULNERABLE=1
elif (( MAJOR == 12 )); then
if (( MINOR == 12 )); then
(( PATCH < 3 )) && VULNERABLE=1
elif (( MINOR == 5 )); then
(( PATCH < 21 )) && VULNERABLE=1
elif (( MINOR > 5 && MINOR < 12 )); then
VULNERABLE=1
elif (( MINOR < 5 && MINOR >= 0 )); then
VULNERABLE=1
fi
fi
if (( VULNERABLE == 1 )); then
echo "VULNERABLE — Fireware ${VERSION} is affected by CVE-2026-86134"
exit 1
else
echo "PATCHED — Fireware ${VERSION} is not affected by CVE-2026-86134"
exit 0
fi