logo

WatchGuard Firebox Vulnerabilities Include Critical Unauthenticated RCE Flaw

ID: e9c08187-2193-584d-a1de-342ee919148c

STIX ID: report--e9c08187-2193-584d-a1de-342ee919148c

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-07-03

Date Updated: 2026-08-06

Author: Do Son

ADMIRALTY:B6
...
...

**Executive summary:** WatchGuard patched seven Firebox vulnerabilities, the most severe being CVE-2026-13368 (CVSS 9.2) — an unauthenticated remote code execution in the IKEv2 Mobile VPN with external LDAP — plus six authenticated high-severity flaws allowing code execution, arbitrary file writes, firmware validation bypass, and local privilege escalation; administrators should prioritize updating affected Fireware OS branches to 2026.2.1 or 12.12.1, restrict Management Web UI access, and address unresolved model-specific issues, noting no confirmed exploitation in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.