10/2/2026 • Security
WatchGuard Firebox Flaw: A DHCP Packet Can Hijack Your Firewall
WatchGuard has patched CVE-2026-81433, a stack buffer overflow in the Firebox's DHCP fingerprinting daemon that lets anyone on your internal network run code on the firewall with no password. Fixed in Fireware 12.12.3, 2026.2.3 and 2026.3.2; not exploited yet.
On 29 September 2026 WatchGuard published fourteen security advisories for Fireware OS, the operating system on its Firebox firewalls, and the one we want to walk you through is not the headline 9.2. It is CVE-2026-81433, an 8.7-rated stack buffer overflow in a small background process called fingerd, the daemon that watches DHCP traffic so the firewall can work out what sort of device has just joined your network. Send it one specially crafted DHCP packet and you can crash it, or run your own code on the firewall. No username, no password, nobody to trick. The catch, and the reason it earns a post of its own, is where that packet has to come from: not the internet, but the network the firewall is there to protect.
What happened, in plain English
Every laptop, phone and printer that joins a network sends a DHCP request to ask for an IP address. Part of that request, DHCP option 60, is a short field in which the device announces what it is. It's called the vendor class identifier, and it's how a network knows a device is a Windows PC rather than a Brother printer. Fireware's fingerd listens to that traffic to fingerprint the devices on your LAN. WatchGuard's own release notes for the fix are specific: Fireware 12.12.3 "resolves a buffer overflow vulnerability in the fingerd daemon when it processes DHCP option 60 requests." The field a device fills in itself turns out to be the field the firewall didn't check the length of.
The nuances, because getting them right is the whole job here:
- No credentials required. The CVSS v4.0 vector is
AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H. No privileges (PR:N), no user interaction (UI:N), no special preconditions (AT:N), and a high impact on confidentiality, integrity and availability of the firewall itself. This is as close to "send packet, own firewall" as a vector gets. - But adjacent, not remote.
AV:Ameans the attacker has to be on a network segment the Firebox is listening to for DHCP. Someone on the internet cannot send this packet to your firewall. That one letter is why WatchGuard rates it 8.7 High rather than Critical, and it's also the lesson of the post, so hold that thought. - It is not being exploited. WatchGuard says it is "not aware of any exploitation of this vulnerability in the wild," and the flaw is not on CISA's Known Exploited Vulnerabilities list as of the 2 October catalogue. It was reported by a researcher, Laurent Gaffié of Secorizon, so this is coordinated disclosure, not an incident write-up.
- The score is the vendor's. The NVD record lists the CVE as "Deferred" with WatchGuard's CVSS 4.0 metric only. There's no independent reassessment yet.
- Affected versions are wide. Fireware OS 12.0 up to but not including 12.12.3, 2025.0 up to but not including 2026.2.3, and 2026.3 up to but not including 2026.3.2. The fixes are 12.12.3, 2026.2.3 and 2026.3.2, all released on 29 September 2026, the same day as the advisory.
- One wrinkle for older Fireboxes. WatchGuard also shipped Fireware 12.5.21 that day for the Firebox T15 and T35, which cannot run anything newer than the 12.5 branch. The advisory for this CVE lists no T15/T35 row, and the 12.5.21 release notes don't name CVE-2026-81433 among the issues it resolves, whereas the other thirteen advisories all list 12.5.21 as a fix. The reasonable reading is that this particular flaw doesn't apply to those models. They still need 12.5.21 for the other thirteen, and if you run a T15 or T35 and want certainty on this one, ask WatchGuard support rather than assume.
The other thirteen, briefly
The same-day batch is one Critical, twelve High and one Medium. The Critical, CVE-2026-86131 at 9.2, is code injection in the BOVPN over TLS client, but its vector carries AT:P: the Firebox has to be configured with a BOVPN over TLS tunnel to a peer the attacker controls, which is not most small businesses. Also in the pile: a stack overflow in the spam-filtering daemon (CVE-2026-18145, 8.6), a SAML authorisation bypass that can grant an unauthorised Mobile VPN with SSL session (CVE-2026-86101, 7.2), and several denial-of-service flaws in the IKE daemon that negotiates VPN keys. WatchGuard reports no exploitation of any of them. One firmware update covers the lot, which is the good news in all this.
Why it matters: your firewall lives on your LAN too
We think of a firewall as facing outward. In a small business the Firebox is also the DHCP server, the DNS forwarder and the default gateway for every internal network, and it listens on every one of those interfaces. "Adjacent network access" sounds reassuring until you list who has it: the guest's phone on your Wi-Fi, the laptop a staff member brought back from home, the smart TV in the meeting room, the contractor's tablet, the printer nobody has updated since 2021. Any of those can send a DHCP packet. That's what they do the moment they connect.
This is the second WatchGuard story in a week with the same shape. Last week's access-point flaws handed an API session to anyone on the LAN; this one hands over the firewall. The pattern worth internalising is that the inside of your network is not a trusted place, and the infrastructure that runs it has to be protected from the devices on it, not just from the internet.
It's also worth remembering that Firebox flaws do get used once details are public. CISA's catalogue added two of them in the last year, CVE-2025-9242 in November 2025 and CVE-2025-14733 in December 2025. Both were internet-facing, which this one is not, but it tells you the attention is there. Our August post on the VPN flaw covers that history.
The honest bit
Fourteen advisories in one day sounds alarming. It's actually what a vendor handling disclosure properly looks like: researcher-found bugs, fixes shipped before the advisories went up, release notes that name every CVE. A buffer overflow in a daemon parsing untrusted input is the oldest bug class in the book, and this year alone we've written about the same class in Cisco, SonicWall and Fortinet gear. No vendor is immune, including the ones we like.
Where a platform choice genuinely helps is in how fast a fix reaches the box. Cloud-managed firewalls can take their updates on a schedule you set rather than when someone remembers. WatchGuard Cloud can upgrade a Firebox running 12.5.2 or later straight from the console, which matters if the box lives in a branch office you don't visit.
What we'd suggest you actually do
- Check the Fireware version on every Firebox today. Move to 12.12.3, 2026.2.3 or 2026.3.2 depending on your branch, or 12.5.21 on a T15 or T35. The upgrade reboots the firewall, so pick a quiet evening, but pick one this week.
- Back up the configuration before you upgrade. The release notes say you can't downgrade the current T and M series models below certain versions, so a config backup is your only easy way back.
- Treat guest and IoT networks as hostile. Put them on their own VLAN, turn on client isolation, and write firewall policies that give guest devices DHCP, DNS and the internet and nothing else. Then test it with a phone instead of assuming.
- Know what's on your LAN. If you pay for Network Discovery, use it. If not, your switch's MAC table will do. The device you can't name is the one to worry about.
- Look at your VPN while you're there. The SAML bypass in the same batch touches Mobile VPN with SSL. Make sure every VPN and admin account has multi-factor authentication, and that the admin interface is only reachable from a management VLAN.
- Subscribe to WatchGuard's advisory feed. psirt.watchguard.com publishes RSS. Fourteen advisories should land in your inbox the day they're published, not in a quarterly review.
- Plan the refresh for anything on the 12.5 branch. A T15 or T35 is already on a legacy firmware train that can't take the current release. It works today, but it has a dead end, and we've seen how that story goes.
The friendly takeaway
This one isn't a five-alarm fire, and we won't dress it up as one. Nobody is known to be exploiting it, it needs an attacker already inside your network, and the fix shipped the same day. What makes it worth your ten minutes is the reminder underneath: the firewall is a computer on your LAN, and everything on your LAN gets to talk to it. Patch it this week, and use the moment to check whether your guest Wi-Fi can reach things it shouldn't.
As always, this is part of us keeping watch so you don't have to. If you'd like a second pair of eyes over your Firebox setup, what's patched, what's segmented and whether the guest network is really isolated, get in touch. No obligation, no hard sell.
References
- WatchGuard PSIRT advisory, CVE-2026-81433: https://psirt.watchguard.com/CVE-2026-81433
- NVD record, CVE-2026-81433: https://nvd.nist.gov/vuln/detail/CVE-2026-81433
- CVE Program record, CVE-2026-81433: https://www.cve.org/CVERecord?id=CVE-2026-81433
- WatchGuard Fireware v12.12.3 release notes (29 September 2026, Security Issues section): https://www.watchguard.com/support/release-notes/fireware/12/en-US/EN_ReleaseNotes_Fireware_12_12_3/Fireware_Release-Notes_v12_12_3.pdf
- WatchGuard Fireware v12.5.21 release notes (29 September 2026, Firebox T15/T35): https://www.watchguard.com/support/release-notes/fireware/12/en-US/EN_ReleaseNotes_Fireware_12_5_21/Fireware_Release-Notes_v12_5_21.pdf
- WatchGuard PSIRT advisory, CVE-2026-86131 (BOVPN over TLS, 9.2): https://psirt.watchguard.com/CVE-2026-86131
- WatchGuard PSIRT advisory index (all fourteen Fireware advisories of 29 to 30 September 2026): https://psirt.watchguard.com/
- CISA Known Exploited Vulnerabilities catalogue: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- WatchGuard Help Center, Network Discovery: https://www.watchguard.com/help/docs/help-center/en-us/Content/en-US/Fireware/system_status/network-discovery_web.html