PatchSiren

WatchGuard CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH WatchGuard CVE published 2026-07-03

CVE-2026-8247

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker on the same local network segment to execute arbitrary code. This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2. The vulnerability has a high severity score and could lead to significant impact if exploited.

MEDIUM WatchGuard CVE published 2026-07-03

CVE-2026-13728

WatchGuard Fireware OS is vulnerable to using a hard-coded encryption key in exception circumstances on FireClusters, affecting Access Portal resource credentials. This issue impacts Fireware OS versions 12.1 through 12.12 and 2025.1 through 2026.2. Devices without Access Portal support or standalone Fireboxes not in a FireCluster are not affected. The vulnerability exists when running on FireClusters wit [truncated]

HIGH WatchGuard CVE published 2026-07-03

CVE-2026-13384

CVE-2026-13384 is an Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process. An authenticated privileged user could execute arbitrary code via specially crafted requests to the Management Web UI. This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 2025.1 up to and including 2026.2. The vulnerability has a CVSS score of 8.6, indicating high severity. Users of affe [truncated]

HIGH WatchGuard CVE published 2026-07-03

CVE-2026-13383

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authenticated privileged user to execute arbitrary code via specially crafted requests to the Management Web UI. This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 2025.1 up to and including 2026.2. The vulnerability has a high CVSS score of 8.6 and is considered HIGH severity. Users of af [truncated]

MEDIUM WatchGuard CVE published 2026-07-03

CVE-2026-13375

CVE-2026-13375 is a Stored XSS vulnerability in WatchGuard Fireware OS, specifically in the Autotask Technology Integration module. The vulnerability is caused by improper neutralization of input during web page generation, allowing Stored XSS attacks. This CVE is an additional unmitigated attack path for CVE-2025-13938. Users of WatchGuard Fireware OS 12.4 up to and including 12.12, 12.5 up to and includ [truncated]

MEDIUM WatchGuard CVE published 2026-07-03

CVE-2026-13373

CVE-2026-13373 is a Stored Cross-Site Scripting (XSS) vulnerability in the WatchGuard Fireware OS, specifically in the Tigerpaw Technology Integration module. This vulnerability is an additional unmitigated attack path for CVE-2025-13936. Affected versions include Fireware OS 12.4 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.

MEDIUM WatchGuard CVE published 2026-07-03

CVE-2026-13371

A medium-severity vulnerability, CVE-2026-13371, allows an authenticated administrator to trigger a denial-of-service condition in the Fireware Management Web UI. This is achieved by sending malformed or crafted data to the put_data endpoint, which performs unsafe deserialization of the attacker-supplied input. The vulnerability has a CVSS score of 6.9, indicating a medium severity level. Administrators a [truncated]

CRITICAL WatchGuard CVE published 2026-07-03

CVE-2026-13368

CVE-2026-13368 is a critical use-after-free vulnerability in WatchGuard Fireware OS. The vulnerability is caused by a race condition in LDAP authentication for the Mobile User VPN with IKEv2. A remote unauthenticated attacker could exploit this vulnerability to execute arbitrary code in the context of the iked process on Fireboxes that have a Mobile VPN with IKEv2 configured to use an external LDAP authen [truncated]

HIGH WatchGuard CVE published 2026-07-03

CVE-2026-13079

CVE-2026-13079 is a local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows. An attacker can exploit this issue to escalate their privileges to NT AUTHORITYSYSTEM on the machine where the client is installed. The vulnerability affects the Mobile VPN with SSL client for Windows up to and including version 2026.2. This issue was reported by a third-party researcher [truncated]

HIGH WatchGuard CVE published 2026-07-03

CVE-2026-13054

A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated attacker to write arbitrary files on the Firebox's filesystem. This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2. The vulnerability has a high CVSS score of 8.6 and is classified as HIGH severity [truncated]

HIGH WatchGuard CVE published 2026-07-03

CVE-2026-13050

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS networkd process could allow an authenticated privileged user to execute arbitrary code via specially crafted requests to the Management Web UI. This vulnerability affects Fireware OS 11.8 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2. The CVSS score is 8.6 with a HIGH severity. Users [truncated]

HIGH Watchguard CVE published 2026-05-06

CVE-2026-6788

CVE-2026-6788 is an Uncontrolled Search Path Element vulnerability in WatchGuard Agent on Windows. This vulnerability allows for the use of malicious files, potentially leading to a compromise of the system. The CVSS score for this vulnerability is 8.5, indicating a high severity level. The vulnerability is caused by the agent's failure to properly validate the search path for files, allowing an attacker [truncated]

HIGH Watchguard CVE published 2026-05-06

CVE-2026-6787

CVE-2026-6787 is a Use of Hard-coded Cryptographic Key vulnerability in WatchGuard Agent on Windows, allowing for Inclusion of Code in Existing Process with a CVSS score of 8.5, indicating high severity. The vulnerability is tracked under CWE-321 and affects WatchGuard Agent versions prior to 1.25.03.0000 on Windows. Organizations using WatchGuard Agent on Windows should prioritize patching due to the hig [truncated]

HIGH WatchGuard CVE published 2026-03-30

CVE-2026-4315

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-30T13:16:22.750Z and has not been modified since then. The vulnerability exists in WatchGuard Fireware OS WebUI due to inadequate validation of requests, allowing a remote attacker to trigger a denial-of-service (DoS) condition by convincing an authenticated administrator into visiting a malicious w [truncated]

HIGH WatchGuard CVE published 2026-03-30

CVE-2026-4266

An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker with write access to the local filesystem to execute arbitrary code in the context of the portald user. This vulnerability specifically affects Firebox platforms that support the Access Portal feature, such as those that do not include the T15 and T35. The CVE record was published on 2026-03-30T13:16:22.573Z and has not [truncated]

MEDIUM WatchGuard CVE published 2026-03-03

CVE-2026-3343

The CVE-2026-3343 vulnerability is a reflected cross-site scripting (XSS) issue in the Watchguard Fireware OS Web UI. This vulnerability allows an attacker to execute malicious JavaScript in the context of an authenticated management user's browser when they click on a specially crafted link. The vulnerability has a CVSS score of 5.1 and a severity of MEDIUM. Watchguard Fireware users and administrators s [truncated]

HIGH WatchGuard CVE published 2026-01-30

CVE-2026-1498

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-01-30T13:15:54.560Z and has not been modified since then. The CVE-2026-1498 vulnerability is an LDAP Injection issue in WatchGuard Fireware OS. This vulnerability may allow a remote unauthenticated attacker to retrieve sensitive information from a connected LDAP authentication server through an exposed [truncated]

Known exploited WatchGuard CVE published 2025-12-19

CVE-2025-14733

CVE-2025-14733 is a WatchGuard Firebox out-of-bounds write vulnerability that CISA added to the Known Exploited Vulnerabilities (KEV) catalog on 2025-12-19. The KEV listing means CISA considers the issue to be known exploited, so affected environments should treat it as a high-priority remediation item. The supplied corpus does not include CVSS scoring or deeper technical details beyond the vulnerability class.

Known exploited WatchGuard CVE published 2025-09-17

CVE-2025-9242

CVE-2025-9242 is a WatchGuard Firebox out-of-bounds write vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2025-11-12. Because it is listed in KEV, defenders should treat it as a priority issue and follow vendor and CISA guidance without delay. CISA set a remediation due date of 2025-12-03.

Known exploited WatchGuard CVE published 2022-04-11

CVE-2022-23176

CVE-2022-23176 is a WatchGuard Firebox and XTM privilege-escalation vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2022-04-11. Because it is listed in the KEV catalog, defenders should treat it as actively exploited and prioritize vendor-directed remediation. The supplied corpus does not include exploit mechanics or a remediation version number, so the safest response is t [truncated]

Known exploited WatchGuard CVE published 2022-03-25

CVE-2022-26318

CVE-2022-26318 is a WatchGuard Firebox and XTM Appliances issue identified by CISA as a Known Exploited Vulnerability (KEV). The available official sources describe it as an arbitrary code execution weakness and direct defenders to apply updates per vendor instructions. Because CISA added it to the KEV catalog on 2022-03-25, organizations should treat it as an urgent remediation item.