CVE-2026-4315

WatchGuard Firebox Cross-Site Request Forgery (CSRF) in Fireware Web UI

High 7.1 CVSS v4.0 › Published 2026-03-30Updated 2026-08-27

Summary #

A Cross-Site Request Forgery (CSRF) vulnerability in the WatchGuard Fireware OS WebUI could allow a remote attacker to trigger a denial-of-service (DoS) condition in the Fireware Web UI by convincing an authenticated administrator into visiting a malicious web page.

Product status #

ProductAffectedNot affected
Fireware OS
Default >= 2025.1, < 2026.2, >= 12.0, < 12.12, >= 11.8, <= 11.12.4+541730>= 2026.2, >= 12.12, > 11.12.4+541730
T15/T35 >= 12.0, < 12.5.18>= 12.5.18
EUCC >= 12.0, < 12.11.9>= 12.11.9

Weakness Type and Impact #

  • CWECWE-352Cross-Site Request Forgery (CSRF)
  • CAPECCAPEC-62Cross Site Request Forgery

Exploitation Status #

WatchGuard is not aware of any exploitation of this issue in the wild.

Solution #

Fireware OS 2026.2, Fireware OS 12.12, Fireware OS 12.5.18, Fireware OS 12.11.9

References #

Credits #

  • Simone Paganessi (https://www.linkedin.com/in/simonepaganessi)finder