cbcvebase.

Watchguard Fireware Os vulnerabilities

69 known vulnerabilities affecting watchguard/fireware_os.

Total CVEs
69
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL7HIGH41MEDIUM21

Vulnerabilities

Page 1 of 4
CVE-2025-9242P1CRITICALCVSS 9.8KEVPoCRansomware≥ 11.0, ≤ 11.12.4+541730≥ 12.0, < 12.11.4+3 more2025-09-17
CVE-2025-9242 [CRITICAL] CWE-787 CVE-2025-9242: An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote u An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was previously configured with the mobi
nvd
CVE-2025-14733P1CRITICALCVSS 9.8KEVRansomware≥ 2025.1, < 2025.1.4≥ 12.0, < 12.11.6+3 more2025-12-19
CVE-2025-14733 [CRITICAL] CWE-787 CVE-2025-14733: An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote u An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was previously configured with the m
nvd
CVE-2026-13086P2CRITICALCVSS 9.3≥ 2025.0, < 2026.2.2≥ 12.0, < 12.12.2+2 more2026-08-28
CVE-2026-13086 [CRITICAL] CWE-121 CVE-2026-13086: A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecate A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecated Mobile Security feature in WatchGuard Fireware OS allows an unauthenticated remote attacker to execute arbitrary code.
nvd
CVE-2026-86131P2CRITICALCVSS 9.8≥ 2026.3, < 2026.3.2≥ 2025.0, < 2026.2.3+2 more2026-09-30
CVE-2026-86131 [CRITICAL] CWE-94 CVE-2026-86131: A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handl A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.
nvd
CVE-2026-19315P2CRITICALCVSS 9.3≥ 2025.0, < 2026.2.2≥ 12.0, < 12.12.2+2 more2026-08-28
CVE-2026-19315 [CRITICAL] CWE-125 CVE-2026-19315: A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthe A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.
nvd
CVE-2026-19318P2CRITICALCVSS 9.3≥ 2025.0, < 2026.2.2≥ 12.0, < 12.12.2+2 more2026-08-28
CVE-2026-19318 [CRITICAL] CWE-121 CVE-2026-19318: A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows a remo A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.
nvd
CVE-2026-19313P2CRITICALCVSS 9.3≥ 2025.0, < 2026.2.2≥ 12.0, < 12.12.2+2 more2026-08-28
CVE-2026-19313 [CRITICAL] CWE-122 CVE-2026-19313: An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenti An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.
nvd
CVE-2026-13368P2HIGHCVSS 8.1≥ 2025.1, < 2026.2.1≥ 12.0, < 12.11.9+1 more2026-07-03
CVE-2026-13368 [HIGH] CWE-416 CVE-2026-13368: WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP a WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2. A remote unauthenticated attacker could exploit this vulnerability to execute arbitrary code in the context of the iked process on Fireboxes that have a Mobile VPN with IKEv2 configured to use an externa
nvd
CVE-2026-78011P3HIGHCVSS 8.7≥ 2025.0, < 2026.2.2≥ 12.0, < 12.12.2+2 more2026-08-28
CVE-2026-78011 [HIGH] CWE-191 CVE-2026-78011: An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauth An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
nvd
CVE-2026-19316P3HIGHCVSS 8.7≥ 2025.0, < 2026.2.2≥ 12.0, < 12.12.2+2 more2026-08-28
CVE-2026-19316 [HIGH] CWE-415 CVE-2026-19316: A double-free vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticat A double-free vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
nvd
CVE-2026-81433P3HIGHCVSS 8.7≥ 2026.3, < 2026.3.2≥ 2025.0, < 2026.2.3+1 more2026-09-30
CVE-2026-81433 [HIGH] CWE-120 CVE-2026-81433: A stack-based buffer overflow vulnerability in WatchGuard Fireware OS's DHCP fingerprinting daemon ( A stack-based buffer overflow vulnerability in WatchGuard Fireware OS's DHCP fingerprinting daemon (fingerd) allows an unauthenticated attacker with adjacent network access to execute arbitrary code or crash the process by sending a specially crafted DHCP packet.
nvd
CVE-2026-8247P3HIGHCVSS 8.8≥ 2025.1, < 2026.2.1≥ 12.0, < 12.12.1+3 more2026-07-03
CVE-2026-8247 [HIGH] CWE-120 CVE-2026-8247: An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker on the same local network segment to execute arbitrary code. This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2.
nvd
CVE-2026-78010P3HIGHCVSS 8.7≥ 2025.0, < 2026.2.2≥ 12.0, < 12.12.2+2 more2026-08-28
CVE-2026-78010 [HIGH] CWE-121 CVE-2026-78010: A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process iallows a rem A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process iallows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
nvd
CVE-2026-19314P3HIGHCVSS 8.7≥ 2025.0, < 2026.2.2≥ 12.0, < 12.12.2+2 more2026-08-28
CVE-2026-19314 [HIGH] CWE-191 CVE-2026-19314: An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauth An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
nvd
CVE-2026-78009P3HIGHCVSS 8.7≥ 2025.0, < 2026.2.2≥ 12.0, < 12.12.2+2 more2026-08-28
CVE-2026-78009 [HIGH] CWE-20 CVE-2026-78009: An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unaut An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
nvd
CVE-2026-78008P3HIGHCVSS 8.6≥ 2025.0, < 2026.2.2≥ 12.0, < 12.12.2+2 more2026-08-28
CVE-2026-78008 [HIGH] CWE-787 CVE-2026-78008: A buffer overflow vulnerability in the WatchGuard Fireware OS Management Web UI allows an authentica A buffer overflow vulnerability in the WatchGuard Fireware OS Management Web UI allows an authenticated administrator with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic.
nvd
CVE-2026-19317P3HIGHCVSS 8.7≥ 2025.0, < 2026.2.2≥ 12.0, < 12.12.2+2 more2026-08-28
CVE-2026-19317 [HIGH] CWE-125 CVE-2026-19317: An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unaut An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
nvd
CVE-2026-18145P3HIGHCVSS 8.6≥ 2026.3, < 2026.3.2≥ 2025.0, < 2026.2.3+2 more2026-09-30
CVE-2026-18145 [HIGH] CWE-121 CVE-2026-18145: A stack-based buffer overflow vulnerability in the spamBlocker (spamd) service of WatchGuard Firewar A stack-based buffer overflow vulnerability in the spamBlocker (spamd) service of WatchGuard Fireware OS allows an authenticated attacker with administrator privileges to crash the service or potentially execute arbitrary code by sending a specially crafted management request.
nvd
CVE-2026-86136P3HIGHCVSS 8.1≥ 2026.0, < 2026.3.2≥ 2025.0, < 2026.2.3+2 more2026-09-30
CVE-2026-86136 [HIGH] CWE-22 CVE-2026-86136: A missing authorization vulnerability in the wgagent management daemon's session initialization func A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted management API request.
nvd
CVE-2026-90441P3HIGHCVSS 8.1≥ 2026.3, < 2026.3.2≥ 2025.0, < 2026.2.3+2 more2026-09-30
CVE-2026-90441 [HIGH] CWE-200 CVE-2026-90441: A missing authorization vulnerability in the wgagent management daemon's session initialization func A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted management API request.
nvd
Watchguard Fireware Os vulnerabilities | cvebase