WatchGuard SAML Flaw: Logged In to the Portal, Let In to the VPN
10/7/2026
WatchGuard has patched CVE-2026-86101, an authorisation bypass in Fireware's SAML login that let a user who was only allowed the Access Portal open a Mobile VPN with SSL session instead. Fixed in Fireware 12.12.3, 2026.2.3, 2026.3.2 and 12.5.21; not exploited.