CVE-2026-13384
- EPSS 0.6%
- Veröffentlicht 02.07.2026 23:05:59
- Zuletzt bearbeitet 28.08.2026 00:16:47
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.
CVE-2026-13383
- EPSS 0.6%
- Veröffentlicht 02.07.2026 23:05:53
- Zuletzt bearbeitet 28.08.2026 00:16:47
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.
CVE-2026-13377
- EPSS 0.17%
- Veröffentlicht 02.07.2026 23:05:32
- Zuletzt bearbeitet 28.08.2026 00:16:47
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS SIP Proxy module allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-6947.
CVE-2026-13376
- EPSS 0.17%
- Veröffentlicht 02.07.2026 23:05:26
- Zuletzt bearbeitet 28.08.2026 00:16:47
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS spamBlocker module allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-1071. ...
CVE-2026-13375
- EPSS 0.17%
- Veröffentlicht 02.07.2026 23:05:20
- Zuletzt bearbeitet 28.08.2026 00:16:47
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Autotask Technology Integration module) allows Stored XSS. This vulnerability is an additional unmitigated attack pat...
CVE-2026-13374
- EPSS 0.17%
- Veröffentlicht 02.07.2026 23:05:13
- Zuletzt bearbeitet 28.08.2026 00:16:47
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (ConnectWise Technology Integration module) allows Stored XSS. This vulnerability is an additional unmitigated attack ...
CVE-2026-13373
- EPSS 0.17%
- Veröffentlicht 02.07.2026 23:05:00
- Zuletzt bearbeitet 28.08.2026 00:16:47
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Tigerpaw Technology Integration module) allows Stored XSS. This vulnerability is an additional unmitigated attack pat...
CVE-2026-13371
- EPSS 0.35%
- Veröffentlicht 02.07.2026 23:04:42
- Zuletzt bearbeitet 28.08.2026 00:16:46
An authenticated administrator can trigger a denial-of-service condition in the Fireware Management Web UI by sending malformed or crafted data to the put_data endpoint, which performs unsafe deserialization of the attacker-supplied input.
CVE-2026-3987
- EPSS 0.68%
- Veröffentlicht 01.04.2026 21:32:30
- Zuletzt bearbeitet 14.08.2026 13:30:09
A path traversal vulnerability in the Fireware OS Web UI on WatchGuard Firebox systems may allow a privileged authenticated remote attacker to execute arbitrary code in the context of an elevated system process.
CVE-2026-4315
- EPSS 0.17%
- Veröffentlicht 30.03.2026 12:38:15
- Zuletzt bearbeitet 28.08.2026 00:18:05
A Cross-Site Request Forgery (CSRF) vulnerability in the WatchGuard Fireware OS WebUI could allow a remote attacker to trigger a denial-of-service (DoS) condition in the Fireware Web UI by convincing an authenticated administrator into visiting a mal...