OFFLINE
Awaiting data
Security intelligence
MinorCritical vulnerability

CVE-2026-86101 (CVSS 7.2)

NVD · officialPublished Sep 30, 2026Risk 23/100

An improper authorization vulnerability in WatchGuard Fireware OS's SAML login process allows a remote, authenticated SAML user with access only to the Access Portal to obtain unauthorized Mobile VPN with SSL access through a specially crafted request.

CVSS
7.2
AV:NetworkAC:LowPR:LowUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source