Watchguard
Watchguard Fireware OS: vulnerabilidades y CVE
Watchguard Fireware OS tiene 22 vulnerabilidades publicadas, 19 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE22
Últimos 12 meses19
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-86132 | Alta (8.2) | 0.36% | — | 29 sept 2026 | An integer underflow vulnerability in the WatchGuard Fireware OS IKEv2 daemon (iked) allows a remote, unauthenticated attacker to crash the process by sending a specially crafted encrypted IKEv2 message negotiated with… |
| CVE-2026-86128 | Alta (8.2) | 0.36% | — | 29 sept 2026 | A NULL pointer dereference vulnerability in Fireware OS's NetFlow packet-processing feature allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted IPv6 packet. |
| CVE-2026-86105 | Media (6) | 0.36% | — | 29 sept 2026 | An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an authenticated, low-privileged Access Portal user to access other web applications they are not authorized for by sending a… |
| CVE-2026-86104 | Alta (8.7) | 0.36% | — | 29 sept 2026 | An uncontrolled resource consumption vulnerability in the Fireware OS login process (wgagent) allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted request. |
| CVE-2026-18105 | Alta (7.1) | 0.23% | — | 29 sept 2026 | An uncontrolled resource consumption vulnerability in Fireware OS's diagnostic tasks feature allows a low-privileged, authenticated user to cause a denial of service of the system's diagnostic tools by repeatedly… |
| CVE-2026-13224 | Alta (8.2) | 0.32% | — | 29 sept 2026 | A path traversal vulnerability in the Fireware OS WebUI management agent allows an authenticated administrator to read or list arbitrary files on the local filesystem by sending a specially crafted management request. |
| CVE-2026-13046 | Alta (7.5) | 0.32% | — | 29 sept 2026 | A deserialization of untrusted data vulnerability in WatchGuard Fireware OS's SAML single sign-on session handling (samld) allows an attacker who has already obtained the ability to write files on the appliance to… |
| CVE-2026-78011 | Alta (8.7) | 0.54% | — | 28 ago 2026 | An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network… |
| CVE-2026-78010 | Alta (8.7) | 0.54% | — | 28 ago 2026 | A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process iallows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially… |
| CVE-2026-78009 | Alta (8.7) | 0.54% | — | 28 ago 2026 | An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted… |
| CVE-2026-78008 | Alta (8.6) | 0.61% | — | 28 ago 2026 | A buffer overflow vulnerability in the WatchGuard Fireware OS Management Web UI allows an authenticated administrator with network access to cause a denial of service (DoS) condition or potentially execute arbitrary… |
| CVE-2026-19318 | Crítica (9.3) | 0.47% | — | 28 ago 2026 | A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic. |
| CVE-2026-19317 | Alta (8.7) | 0.32% | — | 28 ago 2026 | An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted… |
| CVE-2026-19316 | Alta (8.7) | 0.32% | — | 28 ago 2026 | A double-free vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network… |
| CVE-2026-19315 | Crítica (9.3) | 0.46% | — | 28 ago 2026 | A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic. |
| CVE-2026-19314 | Alta (8.7) | 0.32% | — | 28 ago 2026 | An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network… |
| CVE-2026-13086 | Crítica (9.3) | 0.44% | — | 28 ago 2026 | A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecated Mobile Security feature in WatchGuard Fireware OS allows an unauthenticated remote attacker to execute arbitrary code. |
| CVE-2026-81851 | Media (6.9) | 0.41% | — | 28 ago 2026 | A heap-based buffer overflow vulnerability in Fireware OS's iked process allows an authenticated administrator to crash the IKE daemon (iked), resulting in a denial of service, by saving a specially crafted… |
| CVE-2026-1498 | Alta (7) | 0.92% | — | 30 ene 2026 | An LDAP Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensitive information from a connected LDAP authentication server through an exposed authentication or… |
| CVE-2025-6999 | Media (6.9) | 0.45% | — | 15 sept 2025 | An HTTP Request Smuggling [CWE-444] vulnerability in the Authentication portal of WatchGuard Fireware OS allows a remote attacker to evade request parameter sanitation and perform a reflected self-Cross-Site Scripting… |
| CVE-2025-4804 | Media (4.8) | 0.45% | — | 16 may 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS via the spamBlocker module. This vulnerability requires an… |
| CVE-2022-31749 | Media (6.5) | 1.3% | — | 28 ene 2025 | An argument injection vulnerability in the diagnose and import pac commands in WatchGuard Fireware OS before 12.8.1, 12.1.4, and 12.5.10 allows an authenticated remote attacker with unprivileged credentials to upload or… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.