CVE-2026-4315#
WatchGuard Firebox Cross-Site Request Forgery (CSRF) in Fireware Web UI
Summary #
A Cross-Site Request Forgery (CSRF) vulnerability in the WatchGuard Fireware OS WebUI could allow a remote attacker to trigger a denial-of-service (DoS) condition in the Fireware Web UI by convincing an authenticated administrator into visiting a malicious web page.
Product status #
| Product | Affected | Not affected |
|---|---|---|
| Fireware OS | ||
| Default | >= 2025.1, < 2026.2, >= 12.0, < 12.12, >= 11.8, <= 11.12.4+541730 | >= 2026.2, >= 12.12, > 11.12.4+541730 |
| T15/T35 | >= 12.0, < 12.5.18 | >= 12.5.18 |
| EUCC | >= 12.0, < 12.11.9 | >= 12.11.9 |
Weakness Type and Impact #
Exploitation Status #
WatchGuard is not aware of any exploitation of this issue in the wild.
Solution #
Fireware OS 2026.2, Fireware OS 12.12, Fireware OS 12.5.18, Fireware OS 12.11.9
References #
Credits #
- Simone Paganessi (https://www.linkedin.com/in/simonepaganessi)finder