WatchGuard Firebox Vulnerabilities Include Critical Unauthenticated RCE Flaw
ID: e9c08187-2193-584d-a1de-342ee919148c
STIX ID: report--e9c08187-2193-584d-a1de-342ee919148c
Feed Name: securityonline.info
**Executive summary:** WatchGuard patched seven Firebox vulnerabilities, the most severe being CVE-2026-13368 (CVSS 9.2) — an unauthenticated remote code execution in the IKEv2 Mobile VPN with external LDAP — plus six authenticated high-severity flaws allowing code execution, arbitrary file writes, firmware validation bypass, and local privilege escalation; administrators should prioritize updating affected Fireware OS branches to 2026.2.1 or 12.12.1, restrict Management Web UI access, and address unresolved model-specific issues, noting no confirmed exploitation in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
