CVE-2026-13086

Fireware OS Stack-Based Buffer Overflow in Mobile Security epm Endpoint

Critical 9.3 CVSS v4.0 › Published 2026-08-27Updated 2026-08-27

Summary #

A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecated Mobile Security feature in WatchGuard Fireware OS allows an unauthenticated remote attacker to execute arbitrary code.

Impact: A network-adjacent attacker with access to a trusted interface can send a specially crafted JSON-RPC request to the epm service to overflow a stack buffer, overwrite the saved return address, and execute arbitrary code with root privileges without authentication. The lack of a stack canary and use of a non-PIE binary make exploitation via return-oriented programming straightforward, and even unsuccessful exploitation attempts can crash the epm process, causing a denial of service until it is respawned.

Product status #

ProductAffectedNot affected
Fireware OS
Default >= 2025.0, < 2026.2.2, >= 12.0, < 12.12.2>= 2026.2.2, >= 12.12.2
T15/T35 >= 12.0, < 12.5.20>= 12.5.20

Weakness Type and Impact #

Exploitation Status #

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solution #

Fireware OS 2026.2.2, Fireware OS 12.12.2, Fireware OS 12.5.20

References #

    Credits #

    • Mat Powell of TrendAI Zero Day Initiativefinder