CVE-2026-86134
A NULL pointer dereference vulnerability in the WatchGuard Fireware OS authentication process allows a remote, unauthenticated attacker to crash the management daemon by sending a specially request to the login interface, resulting in a denial of service.
- Published Sep 30, 2026
- CVSS 8.7 high
- 0.4% chance of exploitation in the next 30 days (EPSS)
Affected software
In the news
- WatchGuard security advisory (AV26-981) Canadian Centre for Cyber Security ·