PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-13384 WatchGuard CVE debrief

CVE-2026-13384 is an Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process. An authenticated privileged user could execute arbitrary code via specially crafted requests to the Management Web UI. This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 2025.1 up to and including 2026.2. The vulnerability has a CVSS score of 8.6, indicating high severity. Users of affected versions should assess and apply patches or mitigations.

Vendor
WatchGuard
Product
Fireware OS
CVSS
HIGH 8.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-03
Original CVE updated
2026-08-28
Advisory published
2026-07-03
Advisory updated
2026-08-28

Who should care

Users of WatchGuard Fireware OS, particularly those with versions 12.1 through 12.12 and 2025.1 through 2026.2, should assess and potentially apply patches or mitigations. System administrators and security teams responsible for managing WatchGuard Fireware OS deployments should prioritize this vulnerability due to its high severity and potential for code execution.

Technical summary

The CVE-2026-13384 vulnerability is an Out-of-bounds Write issue within the wgagent process of WatchGuard Fireware OS. This could allow an authenticated privileged user to execute arbitrary code by sending specially crafted requests to the Management Web UI. The vulnerability impacts Fireware OS versions 12.1 through 12.12 and 2025.1 through 2026.2. It has a CVSS score of 8.6, indicating high severity. Users should review WatchGuard's official advisory for specific guidance on affected versions and patches.

Defensive priority

High priority due to the potential for code execution by authenticated users and the high CVSS score of 8.6.

Recommended defensive actions

  • Apply patches or updates provided by WatchGuard for Fireware OS versions 12.1 through 12.12 and 2025.1 through 2026.2.
  • Restrict access to the Management Web UI to minimize the risk of exploitation.
  • Monitor systems for unusual activity indicative of potential exploitation.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

Evidence from the NVD and CVE records indicates a high severity vulnerability with a CVSS score of 8.6. The vulnerability is awaiting analysis but has been publicly disclosed. WatchGuard Fireware OS versions 12.1 through 12.12 and 2025.1 through 2026.2 are affected. Users should verify their system configurations and review WatchGuard's official advisory for specific guidance. Defensive measures should include monitoring for unusual activity indicative of potential exploitation and restricting access to the Management Web UI.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-13384 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-13384

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-13384 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-13384

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00021

    5d1c2695-1a31-4499-88ae-e847036fd7e3

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.