CVE-2026-13376: WatchGuard Fireware spamBlocker Stored XSS Vulnerability
WatchGuard's Fireware OS contains a stored cross-site scripting (XSS) vulnerability in the spamBlocker module that allows authenticated attackers to inject malicious scripts into web pages. Because the payload is stored, any user accessing the affected page will execute the attacker's code in their browser. This is a secondary attack path related to the previously disclosed CVE-2025-1071 and requires administrative privilege to exploit, but once injected, affects all viewers of the compromised content.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 4.8 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
- Weaknesses (CWE)
- CWE-79
- Affected products
- 39 configuration(s)
- Published / Modified
- 2026-07-03 / 2026-08-10
NVD description (verbatim)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS spamBlocker module allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-1071. This issue affects Fireware OS 12.0 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.
2 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-13376 is a Stored XSS vulnerability (CWE-79) in the spamBlocker module of WatchGuard Fireware OS. The vulnerability stems from improper input neutralization during web page generation. An authenticated administrator can inject malicious JavaScript that persists in the application, causing it to execute in the browsers of subsequent users who view the affected page. The vulnerability exists as an additional unmitigated code path from CVE-2025-1071. Affected versions include Fireware OS 12.0–12.12, 12.5–12.5.18, and 2025.1–2026.2 across the entire Firebox and FireboxCloud product line.
Business impact
Successful exploitation could allow threat actors with administrative access to compromise the integrity of the firewall's web administration console or user-facing security interfaces. By injecting malicious scripts, attackers could steal session tokens, modify security settings, redirect users to phishing sites, or capture sensitive configuration data. The requirement for high-privilege access limits blast radius, but the stored nature means the compromise persists until actively remediated, affecting all administrative and support staff who interact with the system.
Affected systems
All WatchGuard Fireware OS installations running versions 12.0–12.12, 12.5–12.5.18, or 2025.1–2026.2 are vulnerable. This spans the entire Firebox hardware portfolio (T-series, M-series, NV-series models), FireboxCloud, and FireboxV virtual appliances. Organizations running any variant of these versions should assume they are potentially affected unless they have already patched.
Exploitability
Exploitation requires high-level administrative privileges (PR:H in CVSS terms), making this a threat primarily from insider actors, compromised admin accounts, or adversaries who have already gained network access with elevated credentials. The attack does not require user interaction beyond normal use of the web administration interface (UI:R reflects this expected admin activity). While the barrier to exploitation is moderately high, the stored nature means detection is delayed until the page is viewed, and the attack surface is the spamBlocker module specifically, which may be active in many deployments.
Remediation
Organizations should prioritize patching all affected Fireware OS instances to versions beyond those listed as vulnerable. WatchGuard has released security updates to address this and the related CVE-2025-1071. Patches must be verified against the official WatchGuard security advisory to confirm the specific version numbers that resolve this issue. Interim controls include restricting administrative console access to trusted networks, enforcing multi-factor authentication on admin accounts, and disabling the spamBlocker module if operationally feasible pending patch deployment.
Patch guidance
Contact WatchGuard or consult their official security advisory for the specific patched version numbers applicable to your Fireware OS branch (12.0.x, 12.5.x, or 2025.x/2026.x). Apply patches in a controlled manner, testing in a non-production environment first. Coordinate with WatchGuard support if you require guidance on version compatibility or migration paths. Ensure all Firebox appliances and virtual instances in your environment are updated, including secondary or backup units.
Detection guidance
Monitor web server logs on the Fireware administration interface for unusual script injection patterns in the spamBlocker module configuration pages. Look for HTML entity encoding anomalies, suspicious JavaScript in stored fields, and unexpected modifications to spamBlocker settings. Enable detailed logging of administrative actions and review audit trails for changes made by low-privilege or newly created admin accounts. Intrusion detection systems should flag reflected or stored XSS payloads in HTTP requests to the Fireware web UI, particularly those targeting the spamBlocker module.
Why prioritize this
Although the CVSS score is MEDIUM (4.8), this vulnerability merits prompt attention because it affects core security appliances and represents a persistent compromise mechanism once exploited. The stored XSS nature means it is not one-time impact but continuous exposure. The broad product line affected (dozens of Firebox models plus cloud and virtual variants) increases organizational likelihood of exposure. The relationship to CVE-2025-1071 suggests an escalating attack pattern. Organizations managing multiple WatchGuard instances should treat this as a priority patch cycle rather than a defer-and-monitor case.
Risk score, explained
The CVSS 3.1 score of 4.8 (MEDIUM) reflects limited scope for impact without high privilege, but does not fully capture the operational risk to a security appliance. Confidentiality and integrity are slightly impacted (C:L, I:L), and there is no availability impact. The requirement for high privilege (PR:H) and user interaction (UI:R) suppresses the score. However, in context, compromising the web console of a firewall is operationally significant; the stored persistence and broad product coverage argue for treating this as higher priority than the numeric score alone suggests.
Frequently asked questions
What is the difference between CVE-2026-13376 and CVE-2025-1071?
CVE-2025-1071 was the original vulnerability reported in the spamBlocker module. CVE-2026-13376 represents an additional, unmitigated attack vector in the same module that was not fully addressed by the first fix. Organizations that patched CVE-2025-1071 may still be vulnerable to CVE-2026-13376 and require a new patch. Consult WatchGuard's advisories to understand the relationship between fixes.
Do I need administrative credentials to be exploited by this vulnerability?
Yes, the attacker needs high-level administrative access to the Fireware web console to inject the malicious script. This limits exposure to insider threats, compromised admin accounts, or attackers who have already breached your network and escalated privileges. Protecting administrative accounts with strong passwords and multi-factor authentication significantly reduces risk.
Will patching CVE-2025-1071 also fix CVE-2026-13376?
Not necessarily. Because CVE-2026-13376 is described as an additional unmitigated attack path, patches for the earlier CVE may not cover this new vector. You must verify the specific patch version against WatchGuard's security advisory to confirm that both vulnerabilities are resolved.
How widespread is this vulnerability in WatchGuard deployments?
The vulnerability affects all Fireware OS versions in the 12.0, 12.5, and 2025.1–2026.2 ranges across all Firebox hardware models, FireboxCloud, and FireboxV appliances. If your organization uses WatchGuard firewalls and has not yet patched beyond these versions, you should assume you are vulnerable.
This analysis is based on publicly available vulnerability data as of the publication date. CVSS scores, affected versions, and patch availability are current as reported by WatchGuard and the National Vulnerability Database. Organizations should verify all patch version numbers and affected product details against official WatchGuard security advisories before taking remediation action. This vulnerability intelligence is provided for informational purposes to support security decision-making and does not constitute legal advice or a guarantee of security. Always test patches in a non-production environment and coordinate with your vendors for deployment guidance. Source: NVD (public-domain), retrieved 2026-08-11. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-13373MEDIUMWatchGuard Fireware Stored XSS in Tigerpaw Module
- CVE-2026-13374MEDIUMWatchGuard Fireware ConnectWise XSS Vulnerability – CVSS 4.8 Medium Severity
- CVE-2026-13375MEDIUMWatchGuard Fireware Stored XSS in Autotask Module
- CVE-2026-13377MEDIUMStored XSS in WatchGuard Fireware SIP Proxy
- CVE-2016-20070MEDIUMPrivilege Escalation & Stored XSS in WordPress Booking Calendar Contact Form 1.0.23
- CVE-2018-25384MEDIUMStored XSS in Wikidforum 2.20 Allows Authenticated Attackers to Inject Malicious Scripts
- CVE-2019-25731MEDIUMStored XSS in Zuz Music 2.1 Contact Form
- CVE-2019-25737MEDIUMStored XSS in Live Chat Unlimited 2.8.3 – Admin Session Compromise