Security Advisories
| Severity | Summary | Product / platformAffectedNot affected |
|---|---|---|
| 4.8 | CVE-2026-78616 Dimension Stored XSS via Trusted CA Certificate Configuration | Dimension>= 2.0, < 2.3.1>= 2.3.1 |
| 5.1 | CVE-2026-78498 Dimension Server-Side Request Forgery via Email Server Test Settings | Dimension>= 2.0, < 2.3.1>= 2.3.1 |
| 8.6 | CVE-2026-78612 Dimension SQL Injection in Scheduled Report | Dimension>= 2.0, < 2.3.1>= 2.3.1 |
| 4.6 | CVE-2026-78615 WatchGuard Dimension Reflected DOM-Based XSS in Report Detail Page | Dimension>= 2.0, < 2.3.1>= 2.3.1 |
| 5.1 | CVE-2026-78103 Dimension Log Server Configuration Lock Bypass Vulnerability | Dimension>= 2.0, < 2.3.1>= 2.3.1 |
| 8.6 | CVE-2026-78613 Dimension SQL Injection in Log Viewer | Dimension>= 2.0, < 2.3.1>= 2.3.1 |
| 5.3 | CVE-2026-78495 Dimension Server-Side Request Forgery via Remote Backup Connection Test | Dimension>= 2.0, < 2.3.1>= 2.3.1 |
| 6.3 | CVE-2026-78617 WatchGuard Dimension Web UI Authentication Brute-Force Due to Missing Rate Limiting | Dimension>= 2.0, < 2.3.1>= 2.3.1 |
| 5.1 | CVE-2026-78047 Dimension Stored XSS in Scheduled Report Task | Dimension>= 2.0, < 2.3.1>= 2.3.1 |
| 8.4 | CVE-2026-78610 Dimension CSRF Vulnerability in Administrator Passphrase Change Endpoint | Dimension>= 2.0, < 2.3.1>= 2.3.1 |
| 5.1 | CVE-2026-78499 Dimension SSRF via FTP Server Test Connection | Dimension>= 2.0, < 2.3.1>= 2.3.1 |
| 9.3 | CVE-2026-78174 WatchGuard Dimension Session Hijack via Exposed Session Tokens in Diagnostic Logs | Dimension>= 2.0, < 2.3.1>= 2.3.1 |
| 6.9 | CVE-2026-78618 Dimension Business Logic Flaw Allows Chained Backend Object Operations | Dimension>= 2.0, < 2.3.1>= 2.3.1 |
| 5.1 | CVE-2026-78500 Dimension Blind SSRF via Database Test Connection Feature | Dimension>= 2.0, < 2.3.1>= 2.3.1 |
| 8.7 | CVE-2026-13108 Dimension Denial-of-Service | Dimension>= 2.0, < 2.3.1>= 2.3.1 |
| 8.6 | CVE-2026-78614 Dimension SQL Injection in Audit Report | Dimension>= 2.0, < 2.3.1>= 2.3.1 |
| 9.3 | CVE-2026-19315 Fireware OS Pre-Authentication Type Confusion in iked Allows Remote Code Execution | Fireware OS Default>= 2025.0, < 2026.2.2, >= 12.0, < 12.12.2>= 2026.2.2, >= 12.12.2T15/T35>= 12.0, < 12.5.20>= 12.5.20 |
| 8.7 | CVE-2026-78011 Fireware OS Integer Underflow in Iked Allows Unauthenticated Denial of Service (DoS) | Fireware OS Default>= 2025.0, < 2026.2.2, >= 12.0, < 12.12.2>= 2026.2.2, >= 12.12.2T15/T35>= 12.0, < 12.5.20>= 12.5.20 |
| 8.7 | CVE-2026-19314 Fireware OS Integer Underflow in iked Allows Unauthenticated Denial of Service (DoS) | Fireware OS Default>= 2025.0, < 2026.2.2, >= 12.0, < 12.12.2>= 2026.2.2, >= 12.12.2T15/T35>= 12.0, < 12.5.20>= 12.5.20 |
| 8.7 | CVE-2026-19317 Fireware OS Pre-Authentication Out-of-Bounds Read in iked Allows Denial of Service (DoS) | Fireware OS Default>= 2025.0, < 2026.2.2, >= 12.0, < 12.12.2>= 2026.2.2, >= 12.12.2T15/T35>= 12.0, < 12.5.20>= 12.5.20 |
| 8.7 | CVE-2026-78010 Fireware OS Stack-Based Buffer Overflow in iked Allows Unauthenticated Denial of Service | Fireware OS Default>= 2025.0, < 2026.2.2, >= 12.0, < 12.12.2>= 2026.2.2, >= 12.12.2T15/T35>= 12.0, < 12.5.20>= 12.5.20 |
| 9.3 | CVE-2026-13086 Fireware OS Stack-Based Buffer Overflow in Mobile Security epm Endpoint | Fireware OS Default>= 2025.0, < 2026.2.2, >= 12.0, < 12.12.2>= 2026.2.2, >= 12.12.2T15/T35>= 12.0, < 12.5.20>= 12.5.20 |
| 9.3 | CVE-2026-19318 Fireware OS Pre-Authentication Stack Buffer Overflow in iked Allows Remote Code Execution | Fireware OS Default>= 2025.0, < 2026.2.2, >= 12.0, < 12.12.2>= 2026.2.2, >= 12.12.2T15/T35>= 12.0, < 12.5.20>= 12.5.20 |
| 8.7 | CVE-2026-78009 Fireware OS Out-of-Bounds Read in iked Allows Unauthenticated Denial of Service (DoS) | Fireware OS Default>= 2025.0, < 2026.2.2, >= 12.0, < 12.12.2>= 2026.2.2, >= 12.12.2T15/T35>= 12.0, < 12.5.20>= 12.5.20 |
| 8.7 | CVE-2026-19316 Fireware OS Pre-Authentication Double Free in iked Allows Denial of Service (DoS) | Fireware OS Default>= 2025.0, < 2026.2.2, >= 12.0, < 12.12.2>= 2026.2.2, >= 12.12.2T15/T35>= 12.0, < 12.5.20>= 12.5.20 |
| 8.6 | CVE-2026-78008 Fireware OS Authenticated Buffer Overflow in wgagent | Fireware OS Default>= 2025.0, < 2026.2.2, >= 12.0, < 12.12.2>= 2026.2.2, >= 12.12.2T15/T35>= 12.0, < 12.5.20>= 12.5.20 |
| 9.3 | CVE-2026-19313 Fireware OS Pre-Authentication Heap Buffer Overflow in iked Allows Remote Code Execution | Fireware OS Default>= 2025.0, < 2026.2.2, >= 12.0, < 12.12.2>= 2026.2.2, >= 12.12.2T15/T35>= 12.0, < 12.5.20>= 12.5.20 |
| 6.9 | CVE-2026-81851 Fireware OS Heap-Based Buffer Overflow in iked Allows Denial of Service | Fireware OS Default>= 2025.0, < 2026.2.1, >= 12.0, < 12.12.1>= 2026.2.1, >= 12.12.1T15/T35>= 12.0, < 12.5.18>= 12.5.18EUCC>= 12.0, < 12.11.9>= 12.11.9 |
| 9.3 | CVE-2026-57910 WatchGuard Agent improper authentication allows unauthenticated remote code execution | WatchGuard Agent>= 0, < 1.25.13.0000>= 1.25.13.0000 |
| 9.4 | CVE-2026-57909 WatchGuard Agent path traversal allows unauthenticated remote code execution | WatchGuard Agent>= 0, < 1.25.13.0000>= 1.25.13.0000 |
| 8.6 | CVE-2026-13053 WatchGuard Firebox Authenticated Out of Bounds Write in Management CLI Command Handler | Fireware OS Default>= 2025.1, < 2026.2.1, >= 12.0, < 12.12.1, >= 11.0>= 2026.2.1, >= 12.12.1T15/T35>= 12.0, < 12.5.19>= 12.5.19EUCC>= 12.0, < 12.11.9>= 12.11.9 |
| 8.6 | CVE-2026-13050 WatchGuard Firebox networkd Out of Bounds Write Vulnerability | Fireware OS Default>= 2025.1, < 2026.2.1, >= 12.0, < 12.12.1, >= 11.8>= 2026.2.1, >= 12.12.1T15/T35>= 12.0, < 12.5.19>= 12.5.19EUCC>= 12.0, < 12.11.9>= 12.11.9 |
| 8.6 | CVE-2026-13054 WatchGuard Firebox Arbitrary File Write via Path Traversal in Management Web UI | Fireware OS Default>= 2025.1, < 2026.2.1, >= 12.0, < 12.12.1, >= 11.0>= 2026.2.1, >= 12.12.1T15/T35>= 12.0, < 12.5.19>= 12.5.19EUCC>= 12.0, < 12.11.9>= 12.11.9 |
| 7.3 | CVE-2026-13079 WatchGuard Mobile VPN with SSL Windows Client Local Privilege Escalation | Mobile VPN with SSL Client>= 12.0, < 2026.2.1>= 2026.2.1 |
| 7.7 | CVE-2026-8247 WatchGuard Firebox admd Out of Bounds Write Vulnerability | Fireware OS Default>= 2025.1, < 2026.2.1, >= 12.0, < 12.12.1, >= 11.0>= 2026.2.1, >= 12.12.1T15/T35>= 12.0, < 12.5.19>= 12.5.19EUCC>= 12.0, < 12.11.9>= 12.11.9 |
| 5.9 | CVE-2026-13728 WatchGuard Firebox Hardcoded Fallback Encryption Key in Access Portal Resource Credential Database | Fireware OS Default>= 2025.1, < 2026.2.1, >= 12.0, < 12.12.1>= 2026.2.1, >= 12.12.1EUCC>= 12.0, < 12.11.9>= 12.11.9 |
| 8.7 | CVE-2026-13084 Null Pointer Dereference in WatchGuard Fireware OS iked Process | Fireware OS Default>= 2025.1, < 2026.2.1, >= 12.0, < 12.12.1, >= 11.10.2>= 2026.2.1, >= 12.12.1T15/T35>= 12.0, < 12.5.19>= 12.5.19EUCC>= 12.0, < 12.11.9>= 12.11.9 |
| 9.2 | CVE-2026-13368 WatchGuard Firebox Race Condition and Use-After-Free in Mobile VPN with IKEv2 LDAP Authentication | Fireware OS Default>= 2025.1, < 2026.2.1>= 2026.2.1, >= 12.0, < 12.12.1, >= 11.10.2, <= 11.12.4+541730T15/T35>= 12.0, < 12.5.19>= 12.5.19EUCC>= 12.0, < 12.11.9>= 12.11.9 |
| 8.6 | CVE-2026-13722 WatchGuard Firebox Firmware Image Validation Bypass in WatchGuard Fireware OS | Fireware OS Default>= 2025.1, < 2026.2.1, >= 12.0, < 12.12.1, >= 11.0, <= 11.12.4+541730>= 2026.2.1, >= 12.12.1, > 11.12.4+541730T15/T35>= 12.0—EUCC>= 12.0, < 12.11.9>= 12.11.9 |
| 8.6 | CVE-2026-13384 WatchGuard Firebox wgagent Out of Bounds Write Vulnerability | Fireware OS Default>= 2025.1, < 2026.2.1, >= 12.1, < 12.12.1>= 2026.2.1, >= 12.12.1T15/T35>= 12.1, < 12.5.19>= 12.5.19EUCC>= 12.1, < 12.11.9>= 12.11.9 |
| 8.6 | CVE-2026-13383 WatchGuard Firebox ikestubd Out of Bounds Write Vulnerability | Fireware OS Default>= 2025.1, < 2026.2.1, >= 12.1, < 12.12.1>= 2026.2.1, >= 12.12.1T15/T35>= 12.1, < 12.5.19>= 12.5.19EUCC>= 12.1, < 12.11.9>= 12.11.9 |
| 4.8 | CVE-2026-13377 WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in SIP Proxy Configuration | Fireware OS —>= 12.0, < 12.11.9>= 12.11.9Default>= 2025.1, < 2026.2.1, >= 12.0, < 12.12.1>= 2026.2.1, >= 12.12.1T15/T35>= 12.0, < 12.5.19>= 12.5.19 |
| 4.8 | CVE-2026-13376 WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in spamBlocker Module | Fireware OS Default>= 2025.1, < 2026.2.1, >= 12.0, < 12.12.1>= 2026.2.1, >= 12.12.1T15/T35>= 12.0, < 12.5.19>= 12.5.19EUCC>= 12.0, < 12.11.9>= 12.11.9 |
| 4.8 | CVE-2026-13375 WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Autotask Technology Integration Configuration | Fireware OS Default>= 2025.1, < 2026.2.1, >= 12.4, < 12.12.1, >= 2025.1, <= 2026.2>= 2026.2.1, >= 12.12.1, > 2026.2T15/T35>= 12.4, < 12.5.19>= 12.5.19EUCC>= 12.4, < 12.11.9>= 12.11.9 |
| 4.8 | CVE-2026-13374 WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in ConnectWise Technology Integration Configuration | Fireware OS Default>= 2025.1, < 2026.2.1, >= 12.4, < 12.12.1>= 2026.2.1, >= 12.12.1T15/T35>= 12.4, < 12.5.19>= 12.5.19EUCC>= 12.4, < 12.11.9>= 12.11.9 |
| 4.8 | CVE-2026-13373 WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Tigerpaw Technology Integration Configuration | Fireware OS Default>= 2025.1, < 2026.2.1, >= 12.4, < 12.12.1>= 2026.2.1, >= 12.12.1T15/T35>= 12.4, < 12.5.19>= 12.5.19EUCC>= 12.4, < 12.11.9>= 12.11.9 |
| 6.9 | CVE-2026-13371 WatchGuard Firebox Management Web UI Denial of Service via Unsafe Deserialization | Fireware OS Default>= 2025.1, < 2026.2.1, >= 12.0, < 12.12.1>= 2026.2.1, >= 12.12.1T15/T35>= 12.0, < 12.5.19>= 12.5.19EUCC>= 12.0, < 12.11.9>= 12.11.9 |
| 8.5 | CVE-2026-6788 Uncontrolled search path in PluginLauncher allows SYSTEM code execution in WatchGuard Agent | WatchGuard Agent>= 1.0.0.0, < 1.25.03.0000>= 1.25.03.0000 |
| 8.5 | CVE-2026-6787 Usage of a hard-coded cryptographic key in WatchGuard Agent allows inclusion of code into existing process | WatchGuard Agent>= 1.0.0.0, < 1.25.03.0000>= 1.25.03.0000 |
| 7.1 | CVE-2026-41286 Stack-based Buffer Overflow in WatchGuard Agent Discovery Service on Windows Causes Denial of Service - Variant B | WatchGuard Agent>= 1.0.0.0, < 1.25.03.0000>= 1.25.03.0000 |
| 7.3 | CVE-2026-41288 WatchGuard Agent on Windows Privilege Escalation Vulnerability | WatchGuard Agent>= 1.0.0.0, < 1.25.03.0000>= 1.25.03.0000 |
| 7.1 | CVE-2026-41287 Stack-based Buffer Overflow in WatchGuard Agent Discovery Service on Windows Causes Denial of Service - Variant A | WatchGuard Agent>= 1.0.0.0, < 1.25.03.0000>= 1.25.03.0000 |
| High | WGSA-2026-00013 WatchGuard Agent on Windows Local Privilege Escalation to SYSTEM via Chained Agent Service Vulnerabilities | WatchGuard Agent>= 1.25.0, < 1.25.03.0000>= 1.25.03.0000 |
| 8.6 | CVE-2026-3987 WatchGuard Firebox Arbitrary File Write vis Path Traversal in Fireware Web UI | Fireware OS>= 2025.1, < 2026.2, >= 12.6.1, < 12.12>= 2026.2, >= 12.12 |
| High | WGSA-2026-00008 Multiple Vulnerabilities in AppArmor AKA CrackArmor | DimensionAll versions— |
| 7.1 | CVE-2026-4315 WatchGuard Firebox Cross-Site Request Forgery (CSRF) in Fireware Web UI | Fireware OS Default>= 2025.1, < 2026.2, >= 12.0, < 12.12, >= 11.8, <= 11.12.4+541730>= 2026.2, >= 12.12, > 11.12.4+541730T15/T35>= 12.0, < 12.5.18>= 12.5.18EUCC>= 12.0, < 12.11.9>= 12.11.9 |
| 8.4 | CVE-2026-4266 WatchGuard Firebox Insecure Deserialization in Fireware Access Portal | Fireware OS Default>= 2025.1, < 2026.2, >= 12.1, < 12.12>= 2026.2, >= 12.12EUCC>= 12.1, < 12.11.9>= 12.11.9 |
| 6.9 | CVE-2026-3344 WatchGuard Firebox System Integrity Check Bypass | Fireware OS Default>= 2025.1, < 2026.1.2, >= 12.0, < 12.11.8>= 2026.1.2, >= 12.11.8T15/T35>= 12.0, < 12.5.17>= 12.5.17 |
| 5.1 | CVE-2026-3343 WatchGuard Firebox Reflected Cross-Site-Scripting (XSS) Vulnerability in Fireware Web UI | Fireware OS>= 2025.1, < 2026.1.2, >= 12.7, < 12.11.8>= 2026.1.2, >= 12.11.8 |
| 7.0 | CVE-2026-1498 WatchGuard Firebox LDAP Injection | Fireware OS Default>= 2025.1, < 2026.1, >= 12.0, < 12.11.7>= 2026.1, >= 12.11.7T15/T35>= 12.0, < 12.5.16>= 12.5.16 |
| Med | WGSA-2026-00002 NCP IPSec VPN Client MSI Installer Privilege Escallation (NCPVE-2025-0626) | IPSec VPN Client (NCP)>= 15.0, < 15.33>= 15.33 |
| 9.3 | CVE-2025-14733 WatchGuard Firebox iked Out of Bounds Write Vulnerability | Fireware OS Default>= 2025.1, < 2025.1.4, >= 12.0, < 12.11.6, >= 11.10.2, <= 11.12.4+541730>= 2025.1.4, >= 12.11.6, > 11.12.4+541730T15/T35>= 12.0, < 12.5.15>= 12.5.15FIPS>= 12.0, < 12.3.1+728352>= 12.3.1+728352 |
| 7.5 | CVE-2025-1547 WatchGuard Firebox Authenticated Stack Overflow in Certificate Request Command | Fireware OS Default>= 12.0, <= 12.11.3> 12.11.3T15/T35>= 12.0, < 12.5.13>= 12.5.13 |
| 6.3 | CVE-2025-1910 WatchGuard Mobile VPN with SSL Local Privilege Escalation via Update Package | Mobile VPN with SSL Client>= 11.0, < 12.11.3>= 12.11.3 |
| 4.8 | CVE-2025-6946 WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in IPS Configuration | Fireware OS Default>= 12.0, < 12.11.3>= 12.11.3T15/T35>= 12.0, < 12.5.13>= 12.5.13 |
| 8.2 | CVE-2025-1545 WatchGuard Firebox XPath Injection Vulnerability in Web CGI | Fireware OS Default>= 2025.1, < 2025.1.3, >= 12.0, < 12.11.5, >= 11.11, <= 11.12.4+541730>= 2025.1.3, >= 12.11.5, > 11.12.4+541730T15/T35>= 12.0, < 12.5.14>= 12.5.14 |
| 8.7 | CVE-2025-11838 WatchGuard Firebox iked Memory Corruption Vulnerability | Fireware OS>= 2025.1, <= 2025.1.3, >= 12.6.1, <= 12.11.5> 2025.1.3, > 12.11.5 |
| 6.7 | CVE-2025-13940 WatchGuard Firebox Boot Time System Integrity Check Bypass | Fireware OS>= 2025.1, < 2025.1.3, >= 12.8.1, < 12.11.5>= 2025.1.3, >= 12.11.5 |
| 4.8 | CVE-2025-13939 WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Gateway Wireless Controller | Fireware OS Default>= 2025.1, < 2025.1.3, >= 12.0, < 12.11.5, >= 11.7.2, <= 11.12.4+541730>= 2025.1.3, >= 12.11.5, > 11.12.4+541730T15/T35>= 12.0, < 12.5.14>= 12.5.14 |
| 4.8 | CVE-2025-13938 WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Autotask Technology Integration Configuration | Fireware OS —12.0—Default2025.1, >= 12.0, < 12.11.5>= 12.11.5 |
| 4.8 | CVE-2025-13937 WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in ConnectWise Technology Integration Configuration | Fireware OS Default>= 2025.1, < 2025.1.3, >= 12.0, < 12.11.5>= 2025.1.3, >= 12.11.5T15/T35>= 12.0, < 12.5.14>= 12.5.14 |
| 4.8 | CVE-2025-13936 WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Tigerpaw Technology Integration Configuration | Fireware OS Default2025.1, >= 12.0, < 12.11.5>= 12.11.5T15/T35>= 12.0, < 12.5.14>= 12.5.14 |
| 8.6 | CVE-2025-12196 WatchGuard Firebox Authenticated Out of Bounds Write in Management CLI Ping Command | Fireware OS Default2025.1, >= 12.0, < 12.11.5>= 12.11.5T15/T35>= 12.0, < 12.5.14>= 12.5.14 |
| 8.6 | CVE-2025-12195 WatchGuard Firebox Authenticated Out of Bounds Write in Management CLI IPSec Configuration | Fireware OS Default>= 2025.1, < 2025.1.3, >= 12.0, < 12.11.5, >= 11.0, <= 11.12.4+541730>= 2025.1.3, >= 12.11.5, > 11.12.4+541730T15/T35>= 12.0, < 12.5.14>= 12.5.14 |
| 8.6 | CVE-2025-12026 WatchGuard Firebox Authenticated Out of Bounds Write in certd | Fireware OS Default>= 2025.1, < 2025.1.3, >= 12.0, <= 12.11.5>= 2025.1.3, > 12.11.5T15/T35>= 12.0, < 12.5.14>= 12.5.14 |
| 6.3 | CVE-2025-1549 WatchGuard Mobile VPN with SSL Local Privilege Escallation | Mobile VPN with SSL Client>= 12.0, < 12.11.3>= 12.11.3 |
| 8.9 | CVE-2025-4106 WatchGuard Firebox leftover debug code vulnerability | Fireware OS Default>= 12.0, < 12.11.3>= 12.11.3T15/T35>= 12.0, < 12.5.13>= 12.5.13 |
| 9.3 | CVE-2025-9242 WatchGuard Firebox iked Out of Bounds Write Vulnerability | Fireware OS Default>= 11.0, <= 11.12.4+541730, >= 12.0, < 12.11.4, >= 2025.0, < 2025.1.1> 11.12.4+541730, >= 12.11.4, >= 2025.1.1T15/T35>= 12.0, < 12.5.13>= 12.5.13FIPS>= 12.0, < 12.3.1+722811>= 12.3.1+722811 |
| 4.8 | CVE-2025-6947 WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in SIP Proxy Configuration | Fireware OS Default>= 12.0, < 12.11.3>= 12.11.3T15/T35>= 12.0, < 12.5.13>= 12.5.13 |
| 6.9 | CVE-2025-6999 WatchGuard Firebox Authentication Portal Request Smuggling Vulnerability | Fireware OS>= 12.0, < 12.11.3>= 12.11.3 |
| Med | WGSA-2025-00009 Pre-authentication Denial of Service attack in OpenSSH | Dimension—All versionsFireware OS>= 12.0.0, < 12.11.3>= 12.11.3Secure Wi-Fi—All versions |
| 4.8 | CVE-2025-4805 WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Acces Portal Configuration | Fireware OS>= 12.0, < 12.11.2>= 12.11.2 |
| 4.8 | CVE-2025-4804 WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Hotpot Configuration | Fireware OS Default>= 12.0, < 12.11.2>= 12.11.2T15/T35>= 12.5, < 12.5.13>= 12.5.13 |
| 6.3 | CVE-2025-2782 WatchGuard Terminal Services Agent Local Privilege Escalation via Non-Standard Installation Directory | SSO Terminal Services Agent>= 12.0, < 12.11.2>= 12.11.2 |
| 6.3 | CVE-2025-2781 WatchGuard Mobile VPN with SSL Local Privilege Escalation via Non-Standard Installation Directory | Mobile VPN with SSL Client>= 11.0, < 12.11.2>= 12.11.2 |
| 5.1 | CVE-2025-0178 WatchGaurd Firebox Host Header Injection Vulnerability | Fireware OS Default>= 12.0, < 12.11.1>= 12.11.1T15/T35>= 12.0, < 12.5.13>= 12.5.13 |
| 4.8 | CVE-2025-1239 WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Blocked Sites List | Fireware OS Default>= 12.0, < 12.11.1>= 12.11.1T15/T35>= 12.0, < 12.5.13>= 12.5.13 |
| 4.8 | CVE-2025-1071 WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in spamBlocker Module | Fireware OS Default>= 12.0, < 12.11.1>= 12.11.1T15/T35>= 12.0, < 12.5.13>= 12.5.13 |
| 8.5 | CVE-2024-8424 WatchGuard Endpoint Protection Privilege Escalation in PSANHost Enables Arbitrary File Delete as SYSTEM | Endpoint Security>= 8.00.00.0000, < 8.00.23.0000>= 8.00.23.0000Panda Dome>= 22.00.00, < 22.03.00>= 22.03.00 |
| 8.7 | CVE-2024-6594 WatchGuard Firebox Single Sign-On Client Denial-of-Service | SSO Client>= 12.0, <= 12.7> 12.7 |
| 9.3 | CVE-2024-6593 WatchGuard Firebox Single Sign-On Agent Management Interface Authentication Bypass | SSO Agent>= 12.0, <= 12.10.2> 12.10.2 |
| 9.3 | CVE-2024-6592 WatchGuard Firebox Single Sign-On Agent Protocol Authorization Bypass | SSO Agent>= 12.0, <= 12.10.2> 12.10.2 SSO Client macOS>= 12.0, <= 12.5.4> 12.5.4Windows>= 12.0, <= 12.7> 12.7 |
| High | WGSA-2024-00013 Blast-RADIUS CHAP and PAP Authentication Vulnerability CVE-2024-3596 | DimensionAll versions—Fireware OSAll versions—Secure Wi-Fi—All versions |
| 8.6 | CVE-2024-5974 Firebox Authenticated Buffer Overflow Vulnerability | Fireware OS Default>= 11.9.4, < 12.10.4>= 12.10.4T15/T35>= 12.0, < 12.5.12+701324>= 12.5.12+701324 |
| 8.6 | CVE-2024-4944 Mobile VPN with SSL Local Privilege Escalation Vulnerability | Mobile VPN with SSL Client>= 12.0, < 12.10.4>= 12.10.4 |
| Crit | WGSA-2024-00012 OpenSSH regreSSHion (CVE-2024-6387) | Dimension—All versionsFireware OS>= 12.0, < 12.10.4-b701004>= 12.10.4-b701004Secure Wi-Fi—All versions |
| High | WGSA-2024-00009 CVE-2024-3661 Impact of TunnelVision Vulnerability | IPSec VPN Client (NCP) Windows macOSAll versions—Mobile VPN with SSL Client Windows macOSAll versions— |
| High | WGSA-2024-00008 Diffie-Hellman Key Agreement Protocol Weaknesses CVE-2002-20001 & CVE-2022-40735 | Fireware OS>= 12.0, < 12.10>= 12.10WatchGuard System Manager>= 12.0, < 12.10>= 12.10 |
| Info | WGSA-2024-00007 XZ Utils supply chain compromise (CVE-2024-3094) | ——— |
| Info | WGSA-2024-00005 lighttpd denial of service vulnerability (CVE-2022-41556) | ——— |
| Info | WGSA-2024-00004 Ivanti Connect Secure and Ivanti Policy Secure Gateway Vulnerabilities | ——— |
| High | WGSA-2023-00010 FRR Dynamic Routing Denial of Service Vulenrabilities | Fireware OS>= 12.1.1, < 12.10.1>= 12.10.1 |
| Info | WGSA-2023-00009 Apache Struts Remote Code Execution Vulnerability (CVE-2023-50164) | ——— |
| Crit | WGSA-2023-00008 Heap Buffer Overflow in libwebp WebP Codec | Dimension—All versionsFireware OS—All versionsSecure Wi-Fi—All versionsWatchGuard Cloud—All versions |
| Med | WGSA-2023-00001 OpenSSH Server 9.1 Double Free Vulnerability (CVE-2023-25136) | Dimension—All versionsFireware OS—All versionsSecure Wi-Fi—All versions |
| Info | WGSA-2022-00021 OpenSSL CVE-2022-3602 and CVE-2022-3786 | ——— |
| High | WGSA-2022-00020 OpenVPN Unauthenticated Access To Control Channel Data (CVE-2020-15078) | Fireware OS Default>= 12.0, < 12.8.1>= 12.8.1T15/T35>= 12.5.0, < 12.5.10>= 12.5.10FIPS>= 12.3.1, < 12.3.1-b675192>= 12.3.1-b675192 |
| Med | WGSA-2022-00018 Firebox Local Privilege Escallation Vulnerability | Fireware OS Default>= 12.0, < 12.8.1>= 12.8.1T15/T35>= 12.5, < 12.5.10>= 12.5.10 |
| Med | WGSA-2022-00013 WatchGuard Firebox Authenticated Arbitrary File Read Vulnerability | Fireware OS Default>= 12.0, < 12.8>= 12.8T15/T35>= 12.5, < 12.5.10>= 12.5.10 |
| Med | WGSA-2022-00012 OpenSSL Command Injection Vulnerability (CVE-2022-1292) | ——— |
| High | WGSA-2022-00011 OpenSSL Certificate Processing DoS Vulnerability (CVE-2022-0778) | Dimension—All versions Fireware OS Default>= 12.0, < 12.8-b659436>= 12.8-b659436T15/T35>= 12.5, < 12.5.9-b655824>= 12.5.9-b655824FIPS>= 12.3.0, < 12.3.1_U2>= 12.3.1_U2Secure Wi-Fi—All versionsWatchGuard System Manager>= 12.0, < 12.8-b656510>= 12.8-b656510 |
| Info | WGSA-2022-00010 Java Spring Framework RCE aka Spring4Shell (CVE-2022-22965) | ——— |
| Info | WGSA-2022-00001 Polkit pkexec Local Privilege Escalation Vulnerability (CVE-2021-4034) | ——— |
| High | WGSA-2021-00005 WatchGuard Firebox WebUI Business Logic Vulnerability | Fireware OS Default>= 12.0, < 12.7.2-b652282>= 12.7.2-b652282T15/T35>= 12.5.0, < 12.5.9-b652189>= 12.5.9-b652189FIPS>= 12.3.1, < 12.3.1-b652336>= 12.3.1-b652336 |
| Info | WGSA-2021-00003 Log4j2 Remote Code Execution Vulnerability aka Log4Shell (CVE-2021-44228) | ——— |
| High | WGSA-2021-00002 WatchGuard Mobile VPN with SSL MacOS Privilege Escalation Vulnerability | Mobile VPN with SSL Client>= 12.0, < 12.7.2>= 12.7.2 |
| High | WGSA-2021-00001 WatchGuard Firebox Privilege Escalation Vulnerability | Fireware OS Default>= 12.0, < 12.7.1>= 12.7.1T15/T35>= 12.5.0, < 12.5.8>= 12.5.8FIPS>= 12.3.1, < 12.3.1-B675192>= 12.3.1-B675192 |
| High | WGSA-2019-00002 Inferring and Hijacking VPN-Tunneled TCP Connections | Fireware OS—All versions |
| High | WGSA-2019-00001 TCP SACK PANIC – Kernel Vulnerabilities | Dimension>= 2.0, <= 2.1.2-b596545> 2.1.2-b596545 Fireware OS Default>= 12.0, < 12.5.1-b605447>= 12.5.1-b605447FIPS>= 12.3.1-b584973, < 12.3.1-b675192>= 12.3.1-b675192Secure Wi-Fi>= 8.0.0, < 8.8.0-179>= 8.8.0-179 |
| Info | WGSA-2018-00001 Foreshadow Speculative Execution Attacks | Dimension—All versionsFireware OS—All versions |