CVE-2026-3987#
WatchGuard Firebox Arbitrary File Write vis Path Traversal in Fireware Web UI
Summary #
A path traversal vulnerability in the Fireware OS Web UI on WatchGuard Firebox systems may allow a privileged authenticated remote attacker to execute arbitrary code in the context of an elevated system process.
Product status #
| Product | Affected | Not affected |
|---|---|---|
| Fireware OS | >= 2025.1, < 2026.2, >= 12.6.1, < 12.12 | >= 2026.2, >= 12.12 |
Weakness Type and Impact #
Exploitation Status #
WatchGuard is not aware of any exploitation of this issue in the wild.
Solution #
Fireware OS 2026.2, Fireware OS 12.12
References #
Credits #
- btaolfinder