[NEW] [high] WatchGuard Firebox: Multiple vulnerabilities
A remote, anonymous attacker can exploit multiple vulnerabilities in WatchGuard Firebox to execute arbitrary code, cause a denial of service, manipulate or disclose data, and perform cross-site scripting attacks.
CSIRTS triage
- What
- Multiple vulnerabilities can be exploited by a remote, anonymous attacker to execute arbitrary code, cause denial of service, manipulate or disclose data, and perform cross-site scripting attacks.
- Who is affected
- Deployments of WatchGuard Firebox are affected.
- Urgency
- Remediation is critical due to the high risk of remote exploitation.
- Action
- Update WatchGuard Firebox to the latest version.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Firebox
Get an email when a new Firebox advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2193
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-130500.65% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 48% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-130530.61% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 46% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-130540.62% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 47% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-130790.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-130840.50% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-133681.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 60% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-133710.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-133730.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-133740.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-133750.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-13050 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13053 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13054 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13079 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13084 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13368 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13371 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13373 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13374 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13375 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13376 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13377 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13383 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13384 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13722 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13728 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-8247 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownCVE-2026-8247: An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an unauthenticated att…nvd
- mediumCVE-2026-13728: In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encry…nvd
- unknownCVE-2026-13722: WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image vi…nvd
- highCVE-2026-13384: An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an …nvd
- highCVE-2026-13383: An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an…nvd
- mediumCVE-2026-13377: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vu…nvd
- mediumCVE-2026-13376: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vu…nvd
- mediumCVE-2026-13375: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vu…nvd
- mediumCVE-2026-13374: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vu…nvd
- mediumCVE-2026-13373: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vu…nvd
- unknownCVE-2026-13371: An authenticated administrator can trigger a denial-of-service condition in the Fireware Manag…nvd
- unknownCVE-2026-13368: WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in …nvd
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] Linux Kernel: Multiple vulnerabilities2026-08-25
- medium[NEW] [medium] libTIFF: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Contao: Multiple Vulnerabilities2026-08-25
- medium[NEW] [medium] Django: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Red Hat Enterprise Linux (Apicurio Registry): Multiple Vulnerabilities2026-08-25