CVE-2026-81433: WatchGuard Fireware OS

High severity, CVSS 8.7. EPSS: 0.2% chance of exploitation in the next 30 days.

A stack-based buffer overflow vulnerability in WatchGuard Fireware OS's DHCP fingerprinting daemon (fingerd) allows an unauthenticated attacker with adjacent network access to execute arbitrary code or crash the process by sending a specially crafted DHCP packet.

Affected products

  • WatchGuard Fireware OS: from 2026.3, before 2026.3.2 (fixed in 2026.3.2); from 2025.0, before 2026.2.3 (fixed in 2026.2.3); from 12.0, before 12.12.3 (fixed in 12.12.3)

Published 2026-09-30. Last modified 2026-10-01.