By vendor

Watchguard vulnerabilities

Known CVEs affecting Watchguard products, prioritized by severity, with SEC.co remediation and detection guidance.

11 published vulnerabilities

  • CVE-2026-13079HIGH 7.8

    A flaw in WatchGuard's Mobile VPN with SSL client for Windows lets someone with regular user access on an affected machine escalate their privileges to full system control. An attacker already on the machine—whether a disgruntled employee, someone who gained access through another vulnerability, or a local contractor—could exploit this to gain administrator-level permissions and take over the system. The issue affects all versions of the client up to and including 2026.2.

  • CVE-2026-13053HIGH 7.2

    WatchGuard Fireware OS contains a flaw in its command-line interface (CLI) that allows authenticated administrators with elevated privileges to run arbitrary code on affected firewall devices by submitting a specially crafted command. This is a memory-writing vulnerability that bypasses normal access controls once an attacker has gained administrative credentials.

  • CVE-2026-13054HIGH 7.2

    WatchGuard Firebox firewalls running Fireware OS contain a flaw in their web-based management interface that allows someone with administrative access to upload or write files to unexpected locations on the device. An attacker with valid admin credentials could exploit this to place malicious files, modify configurations, or compromise the firewall's integrity. The vulnerability requires prior authentication, which limits exposure but remains serious given admin accounts' sensitivity.

  • CVE-2026-13383HIGH 7.2

    WatchGuard Fireware OS contains a memory vulnerability in its ikestubd process that allows authenticated administrators to execute arbitrary code through the Management Web UI. An attacker with legitimate privileged credentials can send specially crafted requests that trigger an out-of-bounds write, potentially compromising the firewall's integrity and enabling lateral movement within protected networks. This threat is elevated by the widespread deployment of affected Firebox models across enterprise and mid-market security infrastructures.

  • CVE-2026-13384HIGH 7.2

    WatchGuard Fireware OS contains an out-of-bounds write flaw in the wgagent process that allows authenticated administrators to execute arbitrary code on the firewall. An attacker with valid admin credentials could send specially crafted requests through the Management Web UI to trigger the vulnerability and gain complete control of the device. This is a serious issue because firewalls are critical security infrastructure; compromise of one could allow an attacker to bypass network defenses entirely.

  • CVE-2026-13373MEDIUM 4.8

    WatchGuard Fireware OS contains a stored cross-site scripting (XSS) vulnerability in its Tigerpaw Technology Integration module. An attacker with high privilege access can inject malicious scripts that remain permanently stored in the system and execute when other users view affected pages. This is a secondary exploitation path related to CVE-2025-13936. The vulnerability requires user interaction to trigger and affects a wide range of WatchGuard Firebox appliances and FireboxCloud/FireboxV platforms.

  • CVE-2026-13374MEDIUM 4.8

    WatchGuard's Fireware operating system contains a stored cross-site scripting (XSS) vulnerability in the ConnectWise Technology Integration module. An attacker with high-level administrative privileges can inject malicious scripts that persist in the system and execute in the browsers of other users who view affected pages. This is a secondary attack path related to the previously disclosed CVE-2025-13937. The vulnerability requires user interaction to trigger and affects the confidentiality and integrity of data visible to victims, but does not impact system availability.

  • CVE-2026-13375MEDIUM 4.8

    WatchGuard Fireware OS contains a stored cross-site scripting (XSS) vulnerability in its Autotask Technology Integration module. An authenticated attacker with high privileges can inject malicious scripts that remain in the system and execute in the browsers of other users who interact with affected pages. This is a secondary attack vector for an earlier vulnerability (CVE-2025-13938). The vulnerability requires administrator-level access and user interaction to exploit, limiting immediate risk but warranting attention in environments with untrusted or compromised admin accounts.

  • CVE-2026-13376MEDIUM 4.8

    WatchGuard's Fireware OS contains a stored cross-site scripting (XSS) vulnerability in the spamBlocker module that allows authenticated attackers to inject malicious scripts into web pages. Because the payload is stored, any user accessing the affected page will execute the attacker's code in their browser. This is a secondary attack path related to the previously disclosed CVE-2025-1071 and requires administrative privilege to exploit, but once injected, affects all viewers of the compromised content.

  • CVE-2026-13377MEDIUM 4.8

    WatchGuard Fireware OS contains a stored cross-site scripting (XSS) vulnerability in its SIP Proxy module that allows authenticated attackers with high privileges to inject malicious scripts into web pages. When other users access the affected page, the injected script executes in their browser, potentially compromising their session or stealing sensitive information. This is a follow-on attack vector for an earlier vulnerability (CVE-2025-6947) that was not fully mitigated. The vulnerability affects a broad range of WatchGuard Firebox appliances and FireboxCloud deployments.

  • CVE-2026-13728MEDIUM 4.4

    WatchGuard Fireware OS running on FireCluster deployments may use a hard-coded encryption key under certain rare conditions to encrypt saved credentials for Access Portal resources. If exploited, an attacker with high-level administrative privileges could potentially decrypt and recover those stored credentials. The vulnerability does not affect standalone Fireboxes or devices without Access Portal capability.