Access Point Firmware Releases

This section provides a release history of firmware for access points managed by WatchGuard Cloud (AP130, AP230W, AP330, AP332CR, AP430CR, AP432).

Latest Releases

v3.4.8-1.B747709 — Release Date: 24 September 2026

This firmware release is for all WatchGuard access points managed in WatchGuard Cloud and includes support for current and upcoming new beta features, as well as enhancements and resolved issues.

AP340 Wi-Fi 7 Access Point

This release supports the new AP340 Wi-Fi 7 (802.11be) secure wireless access point. For more details about the AP340, go to the AP340 Hardware Guide.

Access Point Radio Management Enhancements

This feature enables enhanced access point radio management features, including configurable Fast Handover RSSI thresholds, radio band enable/disable controls, and minimum supported data rate settings for individual radios. For more information, go to Configure Access Point Radio Settings.

Access Point Additional Visibility Data

This feature enables additional real-time access point and client data in the Device Summary and Live Status pages, including Airspace Monitoring, AP VPN, and Threat Scan Mode status widgets, and deeper SSID, radio, and network interface statistics. For more information, go to Monitor Access Points.

Neighbor Wi-Fi Report (Beta)

A new Neighbor Wi-Fi Report provides visibility into nearby wireless networks operating in your airspace, including SSID, signal strength, channel, and security details. This helps you identify co-channel interference, optimize channel planning, and troubleshoot connectivity issues. To learn more or to report an issue, go to the Wi-Fi in WatchGuard Cloud Beta test community.

Enhancements

  • Access points now support Link Layer Discovery Protocol (LLDP) to correctly negotiate 802.3at Power over Ethernet (PoE) power with some types of connected switches. [AP-3394]
  • Access points now support SNMP bulk queries from third-party network monitoring systems. [AP-3309]
  • Fast roaming is now supported with WPA3 security modes. [AP-2471]
  • Diagnostic support snapshots now include additional Airspace Monitoring configuration and run-time status information to improve troubleshooting. [AP-3318]

Resolved Issues

  • Operating system boot logs are renamed in diagnostic support snapshots to prevent packet capture transaction logs from overwriting the boot history. [AP-3347]
  • Upgraded OpenSSL to version v3.0.21 to mitigate the HollowByte denial-of-service (DoS) vulnerability. [AP-3331]
  • On AP230W access points, the eth2 LAN interface is no longer randomly disabled after a reboot. [AP-3185]
  • Access points no longer become unresponsive or disconnect from WatchGuard Cloud during continuous system logging. [AP-2643]
  • Wireless clients can no longer bypass captive portal authentication on networks with IPv6 enabled. [AP-3217]
  • AP430CR access points that boot in failsafe mode now correctly assign the static fallback IP address 192.168.99.9 instead of requesting an address via DHCP. [AP-3219]
  • Wireless clients connected to an access point VPN SSID can now access internal network resources when a management VLAN and a captive portal SSID are simultaneously configured. [AP-3103]
  • AP430CR access points no longer cause disabled kernel integrity check alerts in WatchGuard Cloud. [AP-3437]
  • Access points now properly forward multicast traffic to wireless clients connected to VLAN-tagged SSIDs. [AP-2737]
  • Third-party ADIPSYS captive portal splash pages now load correctly when the SSID is configured in NAT mode. [AP-3124]
  • Access points configured with multiple SSIDs no longer return a 500 Internal Error during a reboot performed from WatchGuard Cloud. [AP-3015]
  • Optimized access point memory management during concurrent live-status monitoring sessions to prevent excessive memory usage. [AP-3291]
  • Access points no longer generate incorrect client denied events when MAC access control is disabled on the SSID. [AP-3496]
  • Client connectivity events and client details now correctly display WPA3 Enterprise security mode instead of WPA2 Enterprise for connected wireless clients. [AP-3511]
  • Enhanced security for the command line interface and API service access. [AP-3487, AP-3497, AP-3510]

Previous Releases