Report a Vulnerability

Contacting WatchGuard PSIRT

WatchGuard PSIRT welcomes reports of potential security vulnerabilities in our products and services. You can email a report to security@watchguard.com (encrypted with our PGP public key, this is preferred) or use the form below.

What to include

  • Your name, affiliation/company (if applicable), email, and PGP key (if applicable)
  • The product name, version/model, operating system, and pertinent configuration
  • A detailed description, steps to reproduce, and proof-of-concept code
  • A CVE number if you already have one, and any other information that aids investigation
  • Your disclosure plans and how you'd like to be credited in an advisory

What happens next

A member of WatchGuard PSIRT will investigate your report and contact you by email with any clarifying questions, or to confirm the issue and work toward a resolution and responsible disclosure.

Submit a report

Recommended so we can follow up with questions.
Include steps to reproduce, proof-of-concept, a CVE if assigned, and the affected OS/configuration.
Up to 6 files, each 12 MB max. Files are scanned for malware before they're attached.