CVE-2026-86134
Fireware OS Pre-Authentication NULL Pointer Dereference Allows Remote Denial of Service
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A NULL pointer dereference vulnerability in the WatchGuard Fireware OS authentication process allows a remote, unauthenticated attacker to crash the management daemon by sending a specially request to the login interface, resulting in a denial of service.
| CWE | CWE-476 |
| Vendor | watchguard |
| Product | fireware os |
| Published | Sep 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for watchguard fireware os
Be the first to know when new unknown vulnerabilities affecting watchguard fireware os are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
WatchGuard / Fireware OS
2026.3 < 2026.3.2 2025.0 < 2026.2.3 12.0 < 12.12.3
WatchGuard / Fireware OS
12.0 < 12.5.21
References
Credits
WatchGuard AI Security Research