cbcvebase.

Watchguard Fireware vulnerabilities

70 known vulnerabilities affecting watchguard/fireware.

Total CVEs
70
CISA KEV
4
actively exploited
Public exploits
3
Exploited in wild
4
Severity breakdown
CRITICAL7HIGH35MEDIUM28

Vulnerabilities

Page 2 of 4
CVE-2026-13054P3HIGHCVSS 7.2≥ 11.0, < 12.12.1≥ 2025.1, < 2026.2.1+1 more2026-07-03
CVE-2026-13054 [HIGH] CWE-22 CVE-2026-13054: A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged a A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated attacker to write arbitrary files on the Firebox's filesystem.
nvd
CVE-2025-1547P3HIGHCVSS 7.2≥ 12.0.0, < 12.11.3≥ 12.5, < 12.5.132025-12-04
CVE-2025-1547 [HIGH] CWE-121 CVE-2025-1547: A stack-based buffer overflow vulnerability [CWE-121] in WatchGuard Fireware OS's certificate reques A stack-based buffer overflow vulnerability [CWE-121] in WatchGuard Fireware OS's certificate request command could allow an authenticated privileged user to execute arbitrary code via specially crafted CLI commands.
nvd
CVE-2026-13084P3HIGHCVSS 7.5≥ 12.5, < 12.5.19≥ 11.0.0, < 11.12.4+4 more2026-07-03
CVE-2026-13084 [HIGH] CWE-476 CVE-2026-13084: A null pointer dereference vulnerability in WatchGuard Fireware OS may allow a remote unauthenticate A null pointer dereference vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to create a denial-of-service (DoS) condition by sending specially crafted IKEv2 messages. This vulnerability affects both the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer. This
nvd
CVE-2026-86132P3HIGHCVSS 7.5≥ 12.0, < 12.5.21≥ 12.12, < 12.12.3+2 more2026-09-30
CVE-2026-86132 [HIGH] CWE-191 CVE-2026-86132: An integer underflow vulnerability in the WatchGuard Fireware OS IKEv2 daemon (iked) allows a remote An integer underflow vulnerability in the WatchGuard Fireware OS IKEv2 daemon (iked) allows a remote, unauthenticated attacker to crash the process by sending a specially crafted encrypted IKEv2 message negotiated with an AES-GCM cipher suite.
nvd
CVE-2025-12195P3HIGHCVSS 7.2≥ 11.0, < 12.5.14≥ 11.0, < 12.11.5+1 more2025-12-04
CVE-2025-12195 [HIGH] CWE-787 CVE-2025-12195: An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated pr An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via specially crafted IPSec configuration CLI commands.
nvd
CVE-2026-13053P3HIGHCVSS 7.2≥ 11.0, < 12.12.1≥ 2025.1, < 2026.2.1+1 more2026-07-03
CVE-2026-13053 [HIGH] CWE-787 CVE-2026-13053: An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated pr An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command.
nvd
CVE-2025-12196P3HIGHCVSS 7.2≥ 2025.1, < 2025.1.3≥ 12.0.0, < 12.11.5+1 more2025-12-04
CVE-2025-12196 [HIGH] CWE-787 CVE-2025-12196: An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated pr An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command.
nvd
CVE-2025-12026P3HIGHCVSS 7.2≥ 2025.1, < 2025.1.3≥ 12.0.0, < 12.11.5+1 more2025-12-04
CVE-2025-12026 [HIGH] CWE-787 CVE-2025-12026: An Out-of-bounds Write vulnerability in WatchGuard Fireware OS’s certificate request command could a An Out-of-bounds Write vulnerability in WatchGuard Fireware OS’s certificate request command could allow an authenticated privileged user to execute arbitrary code via specially crafted CLI commands.
nvd
CVE-2026-86104P3HIGHCVSS 7.5≥ 12.0, < 12.5.21≥ 12.12, < 12.12.3+2 more2026-09-30
CVE-2026-86104 [HIGH] CWE-400 CVE-2026-86104: An uncontrolled resource consumption vulnerability in the Fireware OS login process (wgagent) allows An uncontrolled resource consumption vulnerability in the Fireware OS login process (wgagent) allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted request.
nvd
CVE-2026-13383P3HIGHCVSS 7.2≥ 12.1, < 12.12.1≥ 2025.1, < 2026.2.1+1 more2026-07-03
CVE-2026-13383 [HIGH] CWE-787 CVE-2026-13383: An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authe An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.
nvd
CVE-2026-13384P3HIGHCVSS 7.2≥ 12.1, < 12.12.1≥ 2025.1, < 2026.2.1+1 more2026-07-03
CVE-2026-13384 [HIGH] CWE-787 CVE-2026-13384: An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authen An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.
nvd
CVE-2026-13050P3HIGHCVSS 7.2≥ 2025.1, < 2026.2.1≥ 12.5, < 12.5.19+4 more2026-07-03
CVE-2026-13050 [HIGH] CWE-787 CVE-2026-13050: An Out-of-bounds Write vulnerability in WatchGuard Fireware OS networkd process could allow an authe An Out-of-bounds Write vulnerability in WatchGuard Fireware OS networkd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.
nvd
CVE-2026-86134P3HIGHCVSS 7.5≥ 12.0, < 12.5.21≥ 12.12, < 12.12.3+2 more2026-09-30
CVE-2026-86134 [HIGH] CWE-476 CVE-2026-86134: A NULL pointer dereference vulnerability in the WatchGuard Fireware OS authentication process allows A NULL pointer dereference vulnerability in the WatchGuard Fireware OS authentication process allows a remote, unauthenticated attacker to crash the management daemon by sending a specially request to the login interface, resulting in a denial of service.
nvd
CVE-2026-13722P3HIGHCVSS 7.2≥ 2025.1, < 2026.2.1≥ 12.5, ≤ 12.5.18+4 more2026-07-03
CVE-2026-13722 [HIGH] CWE-347 CVE-2026-13722: WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image via the WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image via the backup/restore feature. An authenticated administrator can exploit this vulnerability to install a tampered firmware image.
nvd
CVE-2024-5974P3HIGHCVSS 7.2≥ 11.9.4, < 12.5.12≥ 12.6, < 12.10.4+1 more2024-07-09
CVE-2024-5974 [HIGH] CWE-120 CVE-2024-5974: A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with pr A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with privileged management access to execute arbitrary code with system privileges on the firewall. This issue affects Fireware OS: from 11.9.6 through 12.10.3.
nvd
CVE-2026-86105P3HIGHCVSS 7.1≥ 12.0, < 12.5.21≥ 12.12, < 12.12.3+2 more2026-09-30
CVE-2026-86105 [HIGH] CWE-22 CVE-2026-86105: An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an authe An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an authenticated, low-privileged Access Portal user to access other web applications they are not authorized for by sending a specially crafted request for a different resource which they are authorized to access.
nvd
CVE-2025-11838P3HIGHCVSS 7.5≥ 2025.1, < 2025.1.3≥ 12.0.0, < 12.11.52025-12-04
CVE-2025-11838 [HIGH] CWE-763 CVE-2025-11838: A memory corruption vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker to A memory corruption vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker to trigger a Denial of Service (DoS) condition in the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer.
nvd
CVE-2026-86128P3HIGHCVSS 7.5≥ 12.0, < 12.5.21≥ 12.12, < 12.12.3+2 more2026-09-30
CVE-2026-86128 [HIGH] CWE-476 CVE-2026-86128: A NULL pointer dereference vulnerability in Fireware OS's NetFlow packet-processing feature allows a A NULL pointer dereference vulnerability in Fireware OS's NetFlow packet-processing feature allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted IPv6 packet.
nvd
CVE-2026-86133P3HIGHCVSS 7.5≥ 12.0, < 12.5.21≥ 12.12, < 12.12.3+2 more2026-09-30
CVE-2026-86133 [HIGH] CWE-191 CVE-2026-86133: An integer underflow vulnerability in the WatchGuard Fireware OS IKE daemon (iked) allows a remote a An integer underflow vulnerability in the WatchGuard Fireware OS IKE daemon (iked) allows a remote attacker who has completed the initial IKEv2 handshake to crash the iked process by sending a specially crafted encrypted IKEv2 message, resulting in a denial of service.
nvd
CVE-2022-31791P3HIGHCVSS 7.8≥ 12.0.0, < 12.1.4≥ 12.2.0, < 12.5.10+7 more2022-09-06
CVE-2022-31791 [HIGH] CVE-2022-31791: WatchGuard Firebox and XTM appliances allow a local attacker (that has already obtained shell access WatchGuard Firebox and XTM appliances allow a local attacker (that has already obtained shell access) to elevate their privileges and execute code with root permissions. This is fixed in Fireware OS 12.8.1, 12.5.10, and 12.1.4.
nvd
Watchguard Fireware vulnerabilities | cvebase