WatchGuard patches critical Fireware OS RCE WatchGuard released Fireware OS updates fixing 15 vulnerabilities, including CVE-2026-86131, a critical code injection flaw rated 9.2 that can give root command execution on Firebox appliances. The issue affects BOVPN over TLS client configuration handling when the remote VPN server is attacker-controlled.