watchguard
48 known vulnerabilities affecting watchguard products.
Products
firebox_m270 39
firebox_m290 39
firebox_m370 39
firebox_m390 39
firebox_m470 39
firebox_m4800 39
firebox_m570 39
firebox_m5800 39
firebox_m590 39
firebox_m440 39
firebox_m670 39
firebox_m690 39
firebox_t20 39
firebox_t40 39
firebox_t70 39
firebox_t80 39
firebox_t55 39
fireware 39
fireboxv 38
firebox_t85 38
firebox_t45 38
firebox_m5600 38
firebox_t25 38
firebox_m4600 38
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2025-9242 | Act now | 91.3% | 9.8 | ● | An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process … |
| CVE-2025-14733 | Act now | 26.5% | 9.8 | ● | An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process … |
| CVE-2024-6592 | Medium | 1.2% | 9.1 | An incorrect authorization vulnerability in the protocol communication between t… | |
| CVE-2024-5974 | Medium | 1.0% | 7.2 | A buffer overflow in WatchGuard Fireware OS could may allow an authenticated rem… | |
| CVE-2026-13368 | Medium | 1.0% | 8.1 | WatchGuard Fireware OS contains a race condition leading to a use-after-free vul… | |
| CVE-2026-13383 | Medium | 0.7% | 7.2 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process … | |
| CVE-2026-13384 | Medium | 0.7% | 7.2 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process c… | |
| CVE-2025-12195 | Medium | 0.7% | 7.2 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow… | |
| CVE-2026-3987 | Medium | 0.7% | 7.2 | A path traversal vulnerability in the Fireware OS Web UI on WatchGuard Firebox s… | |
| CVE-2026-13050 | Medium | 0.7% | 7.2 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS networkd process … | |
| CVE-2026-13053 | Medium | 0.6% | 7.2 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow… | |
| CVE-2024-6594 | Medium | 0.6% | 7.5 | Improper Handling of Exceptional Conditions vulnerability in the WatchGuard Sing… | |
| CVE-2025-12196 | Medium | 0.6% | 7.2 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow… | |
| CVE-2026-13054 | Medium | 0.6% | 7.2 | A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI a… | |
| CVE-2024-6593 | Medium | 0.6% | 9.1 | Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka … | |
| CVE-2026-13084 | Medium | 0.5% | 7.5 | A null pointer dereference vulnerability in WatchGuard Fireware OS may allow a r… | |
| CVE-2025-11838 | Medium | 0.5% | 7.5 | A memory corruption vulnerability in WatchGuard Fireware OS may allow an unauthe… | |
| CVE-2025-1545 | Medium | 0.5% | 7.5 | An XPath Injection vulnerability in WatchGuard Fireware OS may allow a remote un… | |
| CVE-2025-12026 | Medium | 0.4% | 7.2 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS’s certificate req… | |
| CVE-2025-1547 | Medium | 0.4% | 7.2 | A stack-based buffer overflow vulnerability [CWE-121] in WatchGuard Fireware OS'… | |
| CVE-2024-4944 | Medium | 0.3% | 7.8 | A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL … | |
| CVE-2026-13722 | Medium | 0.3% | 7.2 | WatchGuard Fireware OS contains a firmware validation bypass when processing a b… | |
| CVE-2026-8247 | Medium | 0.3% | 8.8 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an unau… | |
| CVE-2026-13079 | Medium | 0.1% | 7.8 | A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL… | |
| CVE-2026-6788 | Medium | 0.1% | 7.8 | Uncontrolled Search Path Element vulnerability in WatchGuard Agent on Windows al… | |
| CVE-2026-6787 | Medium | 0.1% | 7.8 | Use of Hard-coded Cryptographic Key vulnerability in WatchGuard Agent on Windows… | |
| CVE-2026-41288 | Medium | 0.1% | 7.8 | Incorrect permission assignment for a resource in the patch management component… | |
| CVE-2026-13371 | Low | 0.4% | 4.9 | An authenticated administrator can trigger a denial-of-service condition in the … | |
| CVE-2025-1071 | Low | 0.3% | 4.8 | A stored cross-site scripting (XSS) vulnerability exists in the management inter… | |
| CVE-2026-3344 | Low | 0.3% | 4.9 | A vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fi… | |
| CVE-2026-13373 | Low | 0.3% | 4.8 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site … | |
| CVE-2026-13374 | Low | 0.3% | 4.8 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site … | |
| CVE-2026-13375 | Low | 0.3% | 4.8 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site … | |
| CVE-2026-13376 | Low | 0.3% | 4.8 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site … | |
| CVE-2026-13377 | Low | 0.3% | 4.8 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site … | |
| CVE-2026-4266 | Low | 0.3% | 6.7 | An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an at… | |
| CVE-2026-41286 | Low | 0.3% | 6.5 | Stack-based Buffer Overflow vulnerability in the WatchGuard Agent discovery serv… | |
| CVE-2026-41287 | Low | 0.3% | 6.5 | Stack-based Buffer Overflow vulnerability in the WatchGuard Agent discovery serv… | |
| CVE-2025-6946 | Low | 0.2% | 4.8 | A stored cross-site scripting (XSS) vulnerability exists in the management inter… | |
| CVE-2025-0178 | Low | 0.2% | 6.1 | An Improper Input Validation vulnerability in WatchGuard Fireware OS allows an a… | |
| CVE-2026-13728 | Low | 0.2% | 4.4 | In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a ha… | |
| CVE-2026-3343 | Low | 0.2% | 6.1 | A reflected cross-site scripting (XSS) vulnerability in the Fireware OS Web UI e… | |
| CVE-2025-13936 | Low | 0.2% | 6.1 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site … | |
| CVE-2025-13937 | Low | 0.2% | 6.1 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site … | |
| CVE-2025-13938 | Low | 0.2% | 6.1 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site … | |
| CVE-2025-13939 | Low | 0.2% | 6.1 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site … | |
| CVE-2026-4315 | Low | 0.2% | 6.5 | A Cross-Site Request Forgery (CSRF) vulnerability in the WatchGuard Fireware OS … | |
| CVE-2025-13940 | Low | 0.1% | 5.5 | An Expected Behavior Violation [CWE-440] vulnerability in WatchGuard Fireware OS… |