cbcvebase.
CVE-2026-4266
published 2026-03-30

CVE-2026-4266: An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to the local filesystem through another…

PriorityP337medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.27%
19.5th percentile
An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to the local filesystem through another vulnerability to execute arbitrary code in the context of the portald user. Note, this vulnerability does not affect Firebox platforms that do not support the Access Portal feature, including the T15 and T35.

Affected

5 ranges
VendorProductVersion rangeFixed in
watchguardfireware>= 12.1 < 12.1212.12
watchguardfireware>= 2025.1 < 2026.22026.2
watchguardfireware_os>= 12.1 < 12.1212.12
watchguardfireware_os>= 12.1 < 12.11.912.11.9
watchguardfireware_os>= 2025.1 < 2026.22026.2

CVSS provenance

nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.4HIGHCVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.