Watchguard
Watchguard Dimension: vulnerabilities and CVEs
Watchguard Dimension has 15 published vulnerabilities, 15 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs15
Last 12 months15
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86135 | High (7) | 0.25% | — | Sep 8, 2026 | A Cross-Site Request Forgery (CSRF) vulnerability in WatchGuard Dimension's database snapshot creation feature allows a remote attacker to trigger unauthorized snapshot creation by tricking an authenticated… |
| CVE-2026-78618 | Medium (6.9) | 0.43% | — | Aug 28, 2026 | A business logic flaw in WatchGuard Dimension allows an authenticated administrator to trigger multiple backend operations within a single logical flow by sending a specially crafted request. |
| CVE-2026-78617 | Medium (6.3) | 0.41% | — | Aug 28, 2026 | WatchGuard Dimension's web login endpoint does not enforce effective rate-limiting or account lockout by default allowing a remote attacker to perform automated password guessing against user accounts. If the account… |
| CVE-2026-78616 | Medium (4.8) | 0.30% | — | Aug 28, 2026 | A Stored Cross-Site Scripting (XSS) vulnerability in WatchGuard Dimension's Trusted CA certificate configuration allows an authenticated administrator to execute arbitrary JavaScript in another authenticated… |
| CVE-2026-78615 | Medium (4.6) | 0.47% | — | Aug 28, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability in WatchGuard Dimension's report detail page allows an attacker to execute arbitrary JavaScript in a authenticated user's browser with a specially crafted URL. |
| CVE-2026-78614 | High (8.6) | 0.71% | — | Aug 28, 2026 | WatchGuard Dimension contains an authenticated SQL injection vulnerability in the audit report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the… |
| CVE-2026-78613 | High (8.6) | 0.62% | — | Aug 28, 2026 | WatchGuard Dimension contains an authenticated SQL injection vulnerability in the log viewer feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the… |
| CVE-2026-78612 | High (8.6) | 0.71% | — | Aug 28, 2026 | WatchGuard Dimension contains an authenticated SQL injection vulnerability in the scheduled report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as… |
| CVE-2026-78610 | High (8.4) | 0.23% | — | Aug 28, 2026 | WatchGuard Dimension's Web UI exposes an administrator passphrase change action that lacks CSRF protection. An attacker who can induce an authenticated global administrator's browser to visit a crafted link or page can… |
| CVE-2026-78499 | Medium (5.1) | 0.44% | — | Aug 28, 2026 | A server-side request forgery (SSRF) vulnerability WatchGuard Dimension FTP Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems. |
| CVE-2026-78495 | Medium (5.3) | 0.39% | — | Aug 28, 2026 | A server-side request forgery (SSRF) vulnerability WatchGuard Dimension Remote Backup Connection Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network… |
| CVE-2026-78174 | Critical (9.3) | 0.43% | — | Aug 28, 2026 | WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-privileged Dimension Administrator can retrieve this log and extract a Super Administrator's session… |
| CVE-2026-78103 | Medium (5.1) | 0.49% | — | Aug 28, 2026 | WatchGuard Dimension provides a client-side lock/unlock UI control for management changes. The server-side configuration endpoint does not enforce this lock/unlock workflow state, allowing an authenticated administrator… |
| CVE-2026-78047 | Medium (5.1) | 0.44% | — | Aug 28, 2026 | A stored cross-site scripting (XSS) vulnerability in WatchGuard Dimension's task scheduling feature allows a low-privileged authenticated administrator to inject arbitrary HTML/JavaScript into these fields, which then… |
| CVE-2026-13108 | High (8.7) | 0.25% | — | Aug 28, 2026 | WatchGuard Dimension is susceptible to a denial-of-service condition when an attacker sends a high volume of TCP SYN packets to the log listening service. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.