← Back

Watchguard

watchguard

115 CVEs • 115 products

Products (115)

Click to collapse
Toggle
Fireware
fireware
Soho Firewall
soho_firewall
Agent
agent
Firebox
firebox
Firebox Ii
firebox_ii
Epp Firmware
epp_firmware
Edr Firmware
edr_firmware
Epdr Firmware
epdr_firmware
Xcs
xcs
Serverlock
serverlock
Firebox 2500
firebox_2500
Firebox 4500
firebox_4500
Legacy Rssa
legacy_rssa
Soho
soho
Vclass
vclass
Server Center
server_center
Rapidstream
rapidstream
Hawkeye G
hawkeye_g
Fireware Xtm
fireware_xtm
Panda Dome
panda_dome
Ap200
ap200
Ap102
ap102
Ap100
ap100
Ap300
ap300
Xmt515
xmt515
Firebox M200
firebox_m200
Firebox M270
firebox_m270
Firebox M290
firebox_m290
Firebox M300
firebox_m300
Firebox M370
firebox_m370
Firebox M390
firebox_m390
Firebox M400
firebox_m400
Firebox M440
firebox_m440
Firebox M470
firebox_m470
Firebox M4800
firebox_m4800
Firebox M500
firebox_m500
Firebox M570
firebox_m570
Firebox M5800
firebox_m5800
Firebox M590
firebox_m590
Firebox M670
firebox_m670
Firebox M690
firebox_m690
Firebox T10
firebox_t10
Firebox T10 D
firebox_t10-d
Firebox T10 W
firebox_t10-w
Firebox T15
firebox_t15
Firebox T15 W
firebox_t15-w
Firebox T20
firebox_t20
Firebox T20 W
firebox_t20-w
Firebox T30
firebox_t30
Firebox T30 W
firebox_t30-w
Firebox T35
firebox_t35
Firebox T35 R
firebox_t35-r
Firebox T35 W
firebox_t35-w
Firebox T40
firebox_t40
Firebox T40 W
firebox_t40-w
Firebox T50
firebox_t50
Firebox T50 W
firebox_t50-w
Firebox T55
firebox_t55
Firebox T55 W
firebox_t55-w
Firebox T70
firebox_t70
Firebox T80
firebox_t80
Fireboxcloud
fireboxcloud
Fireboxv
fireboxv
Xtmv
xtmv
Epp
epp
Edr
edr
Epdr
epdr
Panda Ad360
panda_ad360
Fireboxt Nv5
fireboxt_nv5
Fireboxt T25
fireboxt_t25
Fireboxt T45
fireboxt_t45
Fireboxt T85
fireboxt_t85
Firebox M4600
firebox_m4600
Firebox M5600
firebox_m5600
Firebox Nv5
firebox_nv5

CVEs (115)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Watchguard
1Agent
Aug 10, 2026
May 6, 2026
7.1 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
Stack-based Buffer Overflow vulnerability in the WatchGuard Agent discovery service on Windows allows Overflow Buffers. An unauthenticated attacker on the same local network could exploit this vulnerability to crash the...Show more
Stack-based Buffer Overflow vulnerability in the WatchGuard Agent discovery service on Windows allows Overflow Buffers. An unauthenticated attacker on the same local network could exploit this vulnerability to crash the agent service.Show less
1Watchguard
1Agent
Aug 10, 2026
May 6, 2026
7.1 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
Stack-based Buffer Overflow vulnerability in the WatchGuard Agent discovery service on Windows allows Overflow Buffers. An unauthenticated attacker on the same local network could exploit this vulnerability to crash the...Show more
Stack-based Buffer Overflow vulnerability in the WatchGuard Agent discovery service on Windows allows Overflow Buffers. An unauthenticated attacker on the same local network could exploit this vulnerability to crash the agent service.Show less
1Watchguard
1Fireware
Aug 14, 2026
Apr 1, 2026
8.6 HIGH· v4
7.2 HIGH· v3
N/A· v2
A path traversal vulnerability in the Fireware OS Web UI on WatchGuard Firebox systems may allow a privileged authenticated remote attacker to execute arbitrary code in the context of an elevated system process.
1Watchguard
1Fireware
Aug 28, 2026
Mar 30, 2026
7.1 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
A Cross-Site Request Forgery (CSRF) vulnerability in the WatchGuard Fireware OS WebUI could allow a remote attacker to trigger a denial-of-service (DoS) condition in the Fireware Web UI by convincing an authenticated adm...Show more
A Cross-Site Request Forgery (CSRF) vulnerability in the WatchGuard Fireware OS WebUI could allow a remote attacker to trigger a denial-of-service (DoS) condition in the Fireware Web UI by convincing an authenticated administrator into visiting a malicious web page.Show less
1Watchguard
1Fireware
Aug 28, 2026
Mar 30, 2026
8.4 HIGH· v4
6.7 MEDIUM· v3
N/A· v2
An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to the local filesystem through another vulnerability to execute arbitrary code in the context of the...Show more
An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to the local filesystem through another vulnerability to execute arbitrary code in the context of the portald user. Note, this vulnerability does not affect Firebox platforms that do not support the Access Portal feature, including the T15 and T35.Show less
1Watchguard
1Fireware
Aug 10, 2026
Mar 3, 2026
6.9 MEDIUM· v4
4.9 MEDIUM· v3
N/A· v2
A vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fireware OS filesystem integrity check and maintain limited persistence via a maliciously-crafted firmware update package.
1Watchguard
1Fireware
Aug 10, 2026
Mar 3, 2026
5.1 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
A reflected cross-site scripting (XSS) vulnerability in the Fireware OS Web UI enabled execution of malicious JavaScript in the context of an authenticated management user's browser when they click on a specially crafted...Show more
A reflected cross-site scripting (XSS) vulnerability in the Fireware OS Web UI enabled execution of malicious JavaScript in the context of an authenticated management user's browser when they click on a specially crafted link.Show less
1Watchguard
1Fireware
Jun 17, 2026
Mar 3, 2026
8.6 HIGH· v4
7.2 HIGH· v3
N/A· v2
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an authenticated privileged administrator to execute arbitrary code with root permissions via an exposed management interface. This vulnerability...Show more
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an authenticated privileged administrator to execute arbitrary code with root permissions via an exposed management interface. This vulnerability affects Fireware OS 11.9 up to and including 11.12.4_Update1, 12.0 up to and including 12.11.7 and 2025.1 up to and including 2026.1.1.Show less
1Watchguard
1Fireware
Aug 11, 2026
Dec 19, 2025
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and th...Show more
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured.Show less
1Watchguard
1Fireware
Aug 8, 2026
Dec 4, 2025
4.8 MEDIUM· v4
4.8 MEDIUM· v3
N/A· v2
A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the IPS configuration. An authenticated remote attacker with administrator privileges could exploi...Show more
A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the IPS configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management ninterface of another management user.Show less
1Watchguard
1Fireware
Aug 10, 2026
Dec 4, 2025
7.5 HIGH· v4
7.2 HIGH· v3
N/A· v2
A stack-based buffer overflow vulnerability [CWE-121] in WatchGuard Fireware OS's certificate request command could allow an authenticated privileged user to execute arbitrary code via specially crafted CLI commands.
1Watchguard
1Fireware
Aug 10, 2026
Dec 4, 2025
8.2 HIGH· v4
7.5 HIGH· v3
N/A· v2
An XPath Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensitive information from the Firebox configuration through an exposed authentication or management web...Show more
An XPath Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensitive information from the Firebox configuration through an exposed authentication or management web interface. This vulnerability only affects Firebox systems that have at least one authentication hotspot configured.Show less
1Watchguard
1Fireware
Aug 10, 2026
Dec 4, 2025
6.7 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
An Expected Behavior Violation [CWE-440] vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fireware OS boot time system integrity check and prevent the Firebox from shutting down in the event of...Show more
An Expected Behavior Violation [CWE-440] vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fireware OS boot time system integrity check and prevent the Firebox from shutting down in the event of a system integrity check failure. The on-demand system integrity check in the Fireware Web UI will correctly show a failed system integrity check message in the event of a failure.Show less
1Watchguard
1Fireware
Aug 10, 2026
Dec 4, 2025
4.8 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Gateway Wireless Controller module) allows Stored XSS.
1Watchguard
1Fireware
Aug 10, 2026
Dec 4, 2025
4.8 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Autotask Technology Integration module) allows Stored XSS.
1Watchguard
1Fireware
Aug 10, 2026
Dec 4, 2025
4.8 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (ConnectWise Technology Integration module) allows Stored XSS.
1Watchguard
1Fireware
Aug 10, 2026
Dec 4, 2025
4.8 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Tigerpaw Technology Integration module) allows Stored XSS.
1Watchguard
1Fireware
Aug 10, 2026
Dec 4, 2025
8.6 HIGH· v4
7.2 HIGH· v3
N/A· v2
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command.
1Watchguard
1Fireware
Aug 10, 2026
Dec 4, 2025
8.6 HIGH· v4
7.2 HIGH· v3
N/A· v2
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via specially crafted IPSec configuration CLI commands.
1Watchguard
1Fireware
Aug 10, 2026
Dec 4, 2025
8.6 HIGH· v4
7.2 HIGH· v3
N/A· v2
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS’s certificate request command could allow an authenticated privileged user to execute arbitrary code via specially crafted CLI commands.