
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-13384 is an Out-of-bounds Write vulnerability (CWE-787) in the WatchGuard Fireware OS wgagent process that could allow an authenticated privileged user to execute arbitrary code via specially crafted requests to the Management Web UI. It affects Fireware OS versions 12.1 through 12.12, 12.5 through 12.5.18, and 2025.1 through 2026.2. The vulnerability was published on July 3, 2026, and a patch is available. It carries a CVSS v3.1 score of 7.2 (High) and a CVSS v4.0 score of 8.6 (High) (GitHub Advisory, WatchGuard Advisory).
The root cause is an Out-of-bounds Write (CWE-787) in the wgagent process of WatchGuard Fireware OS, where insufficient bounds checking allows memory to be written beyond the intended buffer boundary. An attacker exploits this by sending specially crafted HTTP requests to the Management Web UI, triggering the memory corruption in the wgagent process. Exploitation requires network access to the Management Web UI and authenticated privileged credentials — no user interaction is needed beyond the attacker's own actions. No public proof-of-concept code has been identified at this time (GitHub Advisory, WatchGuard Advisory).
Successful exploitation allows an authenticated privileged attacker to execute arbitrary code on the affected WatchGuard Fireware OS system, resulting in full compromise of confidentiality, integrity, and availability of the vulnerable system. An attacker with code execution on a network security appliance such as a WatchGuard firewall could intercept or manipulate network traffic, exfiltrate sensitive configuration data (including VPN credentials and firewall rules), disable security controls, and potentially pivot to internal network segments protected by the device (GitHub Advisory, WatchGuard Advisory).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept exploit as of the time of reporting. The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable, reflecting the requirement for authenticated privileged access. The EPSS score is approximately 0.43–0.55%, placing it in roughly the 42nd percentile for exploitation probability within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, WatchGuard Advisory).
wgagent process, embedding a payload designed to trigger an out-of-bounds write in the process's memory buffer.wgagent process to write data beyond the intended buffer boundary.wgagent process on the Fireware OS system (GitHub Advisory, WatchGuard Advisory).wgagent-handled endpoints; crash or error logs from the wgagent process indicating memory faults or unexpected termination.wgagent process; unusual process activity on the Fireware OS management plane.WatchGuard has released patched versions addressing this vulnerability; users should upgrade to Fireware OS 12.12.1 or later (for the 12.x branch) and 2026.2.1 or later (for the 2025.x/2026.x branch). As an immediate workaround, restrict administrative access to the Management Web UI to only authorized, trusted IP addresses using firewall rules or access control lists, and implement network segmentation to prevent broad access to the management interface. Disabling remote management access where not operationally required further reduces the attack surface (WatchGuard Advisory, GitHub Advisory).
Coverage of CVE-2026-13384 has been limited to automated vulnerability tracking platforms and aggregators such as SecurityOnline, INCIBE-CERT, and CVE feed accounts on social media shortly after disclosure. No notable independent researcher commentary or significant media coverage has been identified beyond standard vulnerability database entries and advisory republication.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."