Description
A NULL pointer dereference vulnerability in Fireware OS's NetFlow packet-processing feature allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted IPv6 packet.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Fireware OS 2026.3.2, Fireware OS 2026.2.3, Fireware OS 12.12.3, Fireware OS 12.5.21
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://psirt.watchguard.com/CVE-2026-86128 |
|
History
Tue, 29 Sep 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A NULL pointer dereference vulnerability in Fireware OS's NetFlow packet-processing feature allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted IPv6 packet. | |
| Title | Fireware OS NULL Pointer Dereference in NetFlow IPv6 Traffic Processing Allows Remote Denial of Service | |
| First Time appeared |
Watchguard
Watchguard fireware Os |
|
| Weaknesses | CWE-476 | |
| CPEs | cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Watchguard
Watchguard fireware Os |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: WatchGuard
Published:
Updated: 2026-09-29T23:05:47.408Z
Reserved: 2026-09-05T02:33:08.986Z
Link: CVE-2026-86128
No data.
Status : Received
Published: 2026-09-30T00:16:36.687
Modified: 2026-09-30T00:16:36.687
Link: CVE-2026-86128
No data.
OpenCVE Enrichment
No data.
Weaknesses
