← Browse

CVE-2026-13728

Low

No strong exploitation signal.

CVSS base
4.4 MEDIUM
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
EPSS — probability of exploitation (30 days)
0.2%
14.2th percentile
CISA KEV
Not listed
Weakness / dates
CWE-798
Published 2026-07-03 · modified 2026-08-28

CVSS breakdown

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N

Attack VectorNNetwork
Attack ComplexityHHigh
Privileges RequiredHHigh
User InteractionNNone
ScopeUUnchanged
ConfidentialityHHigh
IntegrityNNone
AvailabilityNNone

Timeline

Description

In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved credentials for Access Portal resources. This vulnerability does not affect devices that do not support the Access Portal feature or standalone Fireboxes not deployed in a FireCluster.

Affected

watchguard

References

Official: NVD · CVE.org