Description
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.
Published: 2026-07-02
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out-of-bounds write vulnerability in the WatchGuard Fireware OS wgagent process enables an authenticated privileged user to execute arbitrary code by sending a specially crafted request to the Management Web UI. The flaw is a classic out-of-bounds write (CWE-787) that causes the process to write beyond the bounds of a buffer, leading directly to arbitrary code execution on the device.

Affected Systems

The vulnerability affects WatchGuard Fireware OS devices that have not applied the vendor’s fixed releases. Any iteration of Fireware OS older than or not equal to the patched versions—2026.2.1, 12.12.1, or 12.5.19—remains vulnerable when the Management Web UI is enabled and accessed by an authenticated privileged user.

Risk and Exploitability

This flaw carries a CVSS score of 8.6, indicating high severity, while an EPSS score of <1 % reflects a low but non‑zero chance of exploitation. Because the exploit requires authenticated privileged access to the Management Web UI, attackers must compromise legitimate credentials or acquire administrative rights. The vulnerability is not listed in CISA KEV, but the potential for arbitrary code execution warrants proactive remediation.

Generated by OpenCVE AI on August 10, 2026 at 23:10 UTC.

Remediation

Vendor Solution

Fireware OS 2026.2.1, Fireware OS 12.12.1, Fireware OS 12.5.19


OpenCVE Recommended Actions

  • Upgrade the device to a Fireware OS release that includes the fix—2026.2.1, 12.12.1, or 12.5.19.
  • Restrict access to the Management Web UI by limiting connectivity to trusted internal networks, VPNs, or dedicated management interfaces, and block exposure to untrusted networks.
  • Enforce least privilege by limiting administrative accounts to those with only necessary permissions, and monitor authentication logs for suspicious activity.

Generated by OpenCVE AI on August 10, 2026 at 23:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Description An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 2025.1 up to and including 2026.2. An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.1
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.5
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:*
References

Mon, 06 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 2025.1 up to and including 2026.2.
Title WatchGuard Firebox wgagent Out of Bounds Write Vulnerability
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-787
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.1
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.5
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Watchguard Firebox M270 Firebox M290 Firebox M295 Firebox M370 Firebox M390 Firebox M395 Firebox M440 Firebox M4600 Firebox M470 Firebox M4800 Firebox M495 Firebox M5600 Firebox M570 Firebox M5800 Firebox M590 Firebox M595 Firebox M670 Firebox M690 Firebox M695 Firebox Nv5 Firebox T115-w Firebox T125 Firebox T125-w Firebox T145 Firebox T145-w Firebox T15 Firebox T185 Firebox T20 Firebox T25 Firebox T35 Firebox T40 Firebox T45 Firebox T55 Firebox T70 Firebox T80 Firebox T85 Fireboxcloud Fireboxv Fireware Fireware Os
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-08-10T17:26:30.372Z

Reserved: 2026-06-25T22:44:10.384Z

Link: CVE-2026-13384

cve-icon Vulnrichment

Updated: 2026-07-06T14:32:53.936Z

cve-icon NVD

Status : Modified

Published: 2026-07-03T00:16:51.893

Modified: 2026-08-10T18:17:40.733

Link: CVE-2026-13384

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T23:15:05Z

Weaknesses