logo

WatchGuard Patches VPN PrivEsc & Firebox LDAP Injection

ID: 4cf503f8-a1b7-59c3-bdc9-7bafc6c07d66

STIX ID: report--4cf503f8-a1b7-59c3-bdc9-7bafc6c07d66

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-02-05

Date Updated: 2026-04-23

Author: Ddos

...
...

WatchGuard published advisories for two security flaws: a local privilege escalation in the Windows Mobile VPN with IPSec MSI installer (NCPVE-2025-0626) that can allow a local user to execute commands as SYSTEM during install/update, and an LDAP Injection in Fireware OS (CVE-2026-1498, CVSS 7.0) that may permit remote unauthenticated attackers to retrieve sensitive LDAP data and potentially authenticate as an LDAP user with a known passphrase; administrators are urged to upgrade to the listed fixed Fireware and client versions immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.