Watchguard
Watchguard Fireware: vulnerabilidades y CVE
Watchguard Fireware tiene 68 vulnerabilidades publicadas, 43 de ellas en los últimos 12 meses. 8 son críticas y 4 figuran en el catálogo de explotación activa de CISA.
CVE68
Últimos 12 meses43
Críticas8
Explotadas activamente4
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-14733 | Crítica (9.3) | 27% | ⚠ Explotación activa | 19 dic 2025 | An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and… |
| CVE-2025-9242 | Crítica (9.3) | 91% | ⚠ Explotación activa | 17 sept 2025 | An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and… |
| CVE-2022-23176 | Alta (8.8) | 11% | ⚠ Explotación activa | 24 feb 2022 | WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access. This vulnerability impacts Fireware OS… |
| CVE-2022-26318 | Crítica (9.8) | 78% | ⚠ Explotación activa | 4 mar 2022 | On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-86134 | Alta (8.7) | 0.42% | — | 30 sept 2026 | A NULL pointer dereference vulnerability in the WatchGuard Fireware OS authentication process allows a remote, unauthenticated attacker to crash the management daemon by sending a specially request to the login… |
| CVE-2026-86133 | Alta (8.2) | 0.34% | — | 30 sept 2026 | An integer underflow vulnerability in the WatchGuard Fireware OS IKE daemon (iked) allows a remote attacker who has completed the initial IKEv2 handshake to crash the iked process by sending a specially crafted… |
| CVE-2026-86101 | Alta (7.2) | 0.21% | — | 30 sept 2026 | An improper authorization vulnerability in WatchGuard Fireware OS's SAML login process allows a remote, authenticated SAML user with access only to the Access Portal to obtain unauthorized Mobile VPN with SSL access… |
| CVE-2026-81433 | Alta (8.7) | 0.20% | — | 30 sept 2026 | A stack-based buffer overflow vulnerability in WatchGuard Fireware OS's DHCP fingerprinting daemon (fingerd) allows an unauthenticated attacker with adjacent network access to execute arbitrary code or crash the process… |
| CVE-2026-18145 | Alta (8.6) | 0.34% | — | 30 sept 2026 | A stack-based buffer overflow vulnerability in the spamBlocker (spamd) service of WatchGuard Fireware OS allows an authenticated attacker with administrator privileges to crash the service or potentially execute… |
| CVE-2026-86131 | Crítica (9.2) | 0.33% | — | 29 sept 2026 | A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting… |
| CVE-2026-19313 | Crítica (9.3) | 0.47% | — | 28 ago 2026 | An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic. |
| CVE-2026-8247 | Alta (7.7) | 0.38% | — | 3 jul 2026 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker on the same local network segment to execute arbitrary code. This vulnerability affects Fireware OS 11.0 up to and… |
| CVE-2026-13728 | Media (5.9) | 0.23% | — | 3 jul 2026 | In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved credentials for Access Portal resources. This vulnerability does not affect devices that do not… |
| CVE-2026-13722 | Alta (8.6) | 0.33% | — | 3 jul 2026 | WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image via the backup/restore feature. An authenticated administrator can exploit this vulnerability to install a tampered firmware… |
| CVE-2026-13384 | Alta (8.6) | 0.72% | — | 3 jul 2026 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI. |
| CVE-2026-13383 | Alta (8.6) | 0.72% | — | 3 jul 2026 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI. |
| CVE-2026-13377 | Media (4.8) | 0.27% | — | 3 jul 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS SIP Proxy module allows Stored XSS. This vulnerability is an additional unmitigated… |
| CVE-2026-13376 | Media (4.8) | 0.27% | — | 3 jul 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS spamBlocker module allows Stored XSS. This vulnerability is an additional unmitigated… |
| CVE-2026-13375 | Media (4.8) | 0.27% | — | 3 jul 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Autotask Technology Integration module) allows Stored XSS. This vulnerability is an… |
| CVE-2026-13374 | Media (4.8) | 0.27% | — | 3 jul 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (ConnectWise Technology Integration module) allows Stored XSS. This vulnerability is an… |
| CVE-2026-13373 | Media (4.8) | 0.27% | — | 3 jul 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Tigerpaw Technology Integration module) allows Stored XSS. This vulnerability is an… |
| CVE-2026-13371 | Media (6.9) | 0.59% | — | 3 jul 2026 | An authenticated administrator can trigger a denial-of-service condition in the Fireware Management Web UI by sending malformed or crafted data to the put_data endpoint, which performs unsafe deserialization of the… |
| CVE-2026-13368 | Crítica (9.2) | 0.94% | — | 3 jul 2026 | WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2. A remote unauthenticated attacker could exploit this vulnerability to… |
| CVE-2026-13084 | Alta (8.7) | 0.61% | — | 3 jul 2026 | A null pointer dereference vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to create a denial-of-service (DoS) condition by sending specially crafted IKEv2 messages. This… |
| CVE-2026-13079 | Alta (7.3) | 0.14% | — | 3 jul 2026 | A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows allows a local attacker to escalate their privileges to NT AUTHORITY\SYSTEM on the machine where the client is… |
| CVE-2026-13054 | Alta (8.6) | 0.60% | — | 3 jul 2026 | A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated attacker to write arbitrary files on the Firebox's filesystem. |
| CVE-2026-13053 | Alta (8.6) | 0.64% | — | 3 jul 2026 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command. |
| CVE-2026-13050 | Alta (8.6) | 0.64% | — | 3 jul 2026 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS networkd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI. |
| CVE-2026-3987 | Alta (8.6) | 1.1% | — | 1 abr 2026 | A path traversal vulnerability in the Fireware OS Web UI on WatchGuard Firebox systems may allow a privileged authenticated remote attacker to execute arbitrary code in the context of an elevated system process. |
| CVE-2026-4315 | Alta (7.1) | 0.24% | — | 30 mar 2026 | A Cross-Site Request Forgery (CSRF) vulnerability in the WatchGuard Fireware OS WebUI could allow a remote attacker to trigger a denial-of-service (DoS) condition in the Fireware Web UI by convincing an authenticated… |
| CVE-2026-4266 | Alta (8.4) | 0.39% | — | 30 mar 2026 | An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to the local filesystem through another vulnerability to execute arbitrary code in the context of the… |
| CVE-2026-3344 | Media (6.9) | 0.45% | — | 3 mar 2026 | A vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fireware OS filesystem integrity check and maintain limited persistence via a maliciously-crafted firmware update package. |
| CVE-2026-3343 | Media (5.1) | 0.34% | — | 3 mar 2026 | A reflected cross-site scripting (XSS) vulnerability in the Fireware OS Web UI enabled execution of malicious JavaScript in the context of an authenticated management user's browser when they click on a specially… |
| CVE-2026-3342 | Alta (8.6) | 0.70% | — | 3 mar 2026 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an authenticated privileged administrator to execute arbitrary code with root permissions via an exposed management interface. This vulnerability… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.