Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

WatchGuard — Vulnerabilities & Security Advisories 63

Browse all 63 CVE security advisories affecting WatchGuard. AI-powered Chinese analysis, POCs, and references for each vulnerability.

WatchGuard Technologies provides network security appliances and cloud-based services primarily designed for small to medium-sized enterprises. The company’s Firebox hardware and Firebox Cloud platforms serve as the core infrastructure for perimeter defense, offering firewall, intrusion prevention, and threat detection capabilities. Historically, the product line has been associated with forty-one recorded Common Vulnerabilities and Exposures (CVEs), predominantly involving remote code execution, cross-site scripting, and privilege escalation flaws. These vulnerabilities often stem from improper input validation or authentication bypasses within the web-based management interface. While no single catastrophic incident has defined the brand’s entire history, the recurring nature of these CVEs highlights persistent challenges in securing embedded web servers. Security researchers frequently analyze these flaws to understand attack vectors against managed security gateways, emphasizing the critical need for rigorous patch management and configuration hardening in deployed environments.

CVE ID Title CVSS Severity Published
CVE-2026-13053 WatchGuard Firebox Authenticated Out of Bounds Write in Management CLI Command Handler — Fireware OS CWE-787 8.6 High 2026-07-02
CVE-2026-13050 WatchGuard Firebox networkd Out of Bounds Write Vulnerability — Fireware OS CWE-787 8.6 High 2026-07-02
CVE-2026-13054 WatchGuard Firebox Arbitrary File Write via Path Traversal in Management Web UI — Fireware OS CWE-22 8.6 High 2026-07-02
CVE-2026-13079 WatchGuard Mobile VPN with SSL Windows Client Local Privilege Escalation — Mobile VPN with SSL Client CWE-732 7.3 High 2026-07-02
CVE-2026-8247 WatchGuard Firebox admd Out of Bounds Write Vulnerability — Fireware OS CWE-120 7.7 High 2026-07-02
CVE-2026-13728 WatchGuard Firebox Hardcoded Fallback Encryption Key in Access Portal Resource Credential Database — Fireware OS CWE-798 5.9 Medium 2026-07-02
CVE-2026-13084 Null Pointer Dereference in WatchGuard Fireware OS iked Process — Fireware OS CWE-476 8.7 High 2026-07-02
CVE-2026-13368 WatchGuard Firebox Race Condition and Use-After-Free in Mobile VPN with IKEv2 LDAP Authentication — Fireware OS CWE-416 9.2 Critical 2026-07-02
CVE-2026-13722 WatchGuard Firebox Firmware Image Validation Bypass in WatchGuard Fireware OS — Fireware OS CWE-347 8.6 High 2026-07-02
CVE-2026-13384 WatchGuard Firebox wgagent Out of Bounds Write Vulnerability — Fireware OS CWE-787 8.6 High 2026-07-02
CVE-2026-13383 WatchGuard Firebox ikestubd Out of Bounds Write Vulnerability — Fireware OS CWE-787 8.6 High 2026-07-02
CVE-2026-13377 WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in SIP Proxy Configuration — Fireware OS CWE-79 4.8 Medium 2026-07-02
CVE-2026-13376 WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in spamBlocker Module — Fireware OS CWE-79 4.8 Medium 2026-07-02
CVE-2026-13375 WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Autotask Technology Integration Configuration — Fireware OS CWE-79 4.8 Medium 2026-07-02
CVE-2026-13374 WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in ConnectWise Technology Integration Configuration — Fireware OS CWE-79 4.8 Medium 2026-07-02
CVE-2026-13373 WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Tigerpaw Technology Integration Configuration — Fireware OS CWE-79 4.8 Medium 2026-07-02
CVE-2026-13371 WatchGuard Firebox Management Web UI Denial of Service via Unsafe Deserialization — Fireware OS CWE-502 6.9 Medium 2026-07-02
CVE-2026-6788 Uncontrolled search path in PluginLauncher allows SYSTEM code execution in WatchGuard Agent — WatchGuard Agent CWE-427 8.5 High 2026-05-06
CVE-2026-6787 Usage of a hard-coded cryptographic key in WatchGuard Agent allows inclusion of code into existing process — WatchGuard Agent CWE-321 8.5 High 2026-05-06
CVE-2026-41286 Stack-based Buffer Overflow in WatchGuard Agent Discovery Service on Windows Causes Denial of Service - Variant B — WatchGuard Agent CWE-121 7.1 High 2026-05-06
CVE-2026-41288 WatchGuard Agent on Windows Privilege Escalation Vulnerability — WatchGuard Agent CWE-732 7.3 High 2026-05-06
CVE-2026-41287 Stack-based Buffer Overflow in WatchGuard Agent Discovery Service on Windows Causes Denial of Service - Variant A — WatchGuard Agent CWE-121 7.1 High 2026-05-06
CVE-2026-3987 WatchGuard Firebox Arbitrary File Write vis Path Traversal in Fireware Web UI — Fireware OS CWE-22 8.6 High 2026-04-01
CVE-2026-4315 WatchGuard Firebox Cross-Site Request Forgery (CSRF) in Fireware Web UI — Fireware OS CWE-352 7.1 High 2026-03-30
CVE-2026-4266 WatchGuard Firebox Insecure Deserialization in Fireware Access Portal — Fireware OS CWE-502 8.4 High 2026-03-30
CVE-2026-3344 WatchGuard Firebox System Integrity Check Bypass — Fireware OS CWE-440 6.9 Medium 2026-03-03
CVE-2026-3343 WatchGuard Firebox Reflected Cross-Site-Scripting (XSS) Vulnerability in Fireware Web UI — Fireware OS CWE-79 5.1 Medium 2026-03-03
CVE-2026-3342 WatchGuard Firebox Out of Bounds Write Vulnerability — Fireware OS CWE-787 7.2AI High AI 2026-03-03
CVE-2026-1498 WatchGuard Firebox LDAP Injection — Fireware OS CWE-90 7.0 High 2026-01-30
CVE-2025-14733 WatchGuard Firebox iked Out of Bounds Write Vulnerability — Fireware OS CWE-787 9.3 Critical 2025-12-19

This page lists every published CVE security advisory associated with WatchGuard. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.