CVE-2026-13384
WatchGuard Firebox vulnerability analysis and mitigation

Overview

CVE-2026-13384 is an Out-of-bounds Write vulnerability (CWE-787) in the WatchGuard Fireware OS wgagent process that could allow an authenticated privileged user to execute arbitrary code via specially crafted requests to the Management Web UI. It affects Fireware OS versions 12.1 through 12.12, 12.5 through 12.5.18, and 2025.1 through 2026.2. The vulnerability was published on July 3, 2026, and a patch is available. It carries a CVSS v3.1 score of 7.2 (High) and a CVSS v4.0 score of 8.6 (High) (GitHub Advisory, WatchGuard Advisory).

Technical details

The root cause is an Out-of-bounds Write (CWE-787) in the wgagent process of WatchGuard Fireware OS, where insufficient bounds checking allows memory to be written beyond the intended buffer boundary. An attacker exploits this by sending specially crafted HTTP requests to the Management Web UI, triggering the memory corruption in the wgagent process. Exploitation requires network access to the Management Web UI and authenticated privileged credentials — no user interaction is needed beyond the attacker's own actions. No public proof-of-concept code has been identified at this time (GitHub Advisory, WatchGuard Advisory).

Impact

Successful exploitation allows an authenticated privileged attacker to execute arbitrary code on the affected WatchGuard Fireware OS system, resulting in full compromise of confidentiality, integrity, and availability of the vulnerable system. An attacker with code execution on a network security appliance such as a WatchGuard firewall could intercept or manipulate network traffic, exfiltrate sensitive configuration data (including VPN credentials and firewall rules), disable security controls, and potentially pivot to internal network segments protected by the device (GitHub Advisory, WatchGuard Advisory).

Exploitability

There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept exploit as of the time of reporting. The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable, reflecting the requirement for authenticated privileged access. The EPSS score is approximately 0.43–0.55%, placing it in roughly the 42nd percentile for exploitation probability within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, WatchGuard Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or internally accessible WatchGuard Fireware OS Management Web UI instances running affected versions (12.1–12.12, 12.5–12.5.18, or 2025.1–2026.2) using network scanning tools or Shodan.
  2. Credential Acquisition: Obtain valid privileged administrative credentials for the Management Web UI through phishing, credential stuffing, or insider access — exploitation requires authenticated privileged access.
  3. Craft Malicious Request: Construct a specially crafted HTTP request targeting the Management Web UI endpoint handled by the wgagent process, embedding a payload designed to trigger an out-of-bounds write in the process's memory buffer.
  4. Trigger Vulnerability: Submit the crafted request to the Management Web UI while authenticated, causing the wgagent process to write data beyond the intended buffer boundary.
  5. Achieve Code Execution: The memory corruption from the out-of-bounds write is leveraged to redirect execution flow and run arbitrary code with the privileges of the wgagent process on the Fireware OS system (GitHub Advisory, WatchGuard Advisory).

Indicators of compromise

  • Network: Unusual or malformed HTTP requests to the WatchGuard Management Web UI from unexpected source IPs or at unusual times; unexpected outbound connections from the firewall management interface to external hosts.
  • Logs: Anomalous entries in Management Web UI access logs showing repeated or malformed requests to wgagent-handled endpoints; crash or error logs from the wgagent process indicating memory faults or unexpected termination.
  • Process: Unexpected child processes spawned by the wgagent process; unusual process activity on the Fireware OS management plane.
  • File System: Unexpected modifications to Fireware OS configuration files or introduction of new scripts/binaries in system directories.

Mitigation and workarounds

WatchGuard has released patched versions addressing this vulnerability; users should upgrade to Fireware OS 12.12.1 or later (for the 12.x branch) and 2026.2.1 or later (for the 2025.x/2026.x branch). As an immediate workaround, restrict administrative access to the Management Web UI to only authorized, trusted IP addresses using firewall rules or access control lists, and implement network segmentation to prevent broad access to the management interface. Disabling remote management access where not operationally required further reduces the attack surface (WatchGuard Advisory, GitHub Advisory).

Community reactions

Coverage of CVE-2026-13384 has been limited to automated vulnerability tracking platforms and aggregators such as SecurityOnline, INCIBE-CERT, and CVE feed accounts on social media shortly after disclosure. No notable independent researcher commentary or significant media coverage has been identified beyond standard vulnerability database entries and advisory republication.

Additional resources


SourceThis report was generated using AI

Related WatchGuard Firebox vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-13722HIGH8.6
  • WatchGuard Firebox logoWatchGuard Firebox
  • cpe:2.3:o:watchguard:fireware
NoYesJul 03, 2026
CVE-2026-13384HIGH8.6
  • WatchGuard Firebox logoWatchGuard Firebox
  • cpe:2.3:o:watchguard:fireware
NoYesJul 03, 2026
CVE-2026-13383HIGH8.6
  • WatchGuard Firebox logoWatchGuard Firebox
  • cpe:2.3:o:watchguard:fireware
NoYesJul 03, 2026
CVE-2026-8247HIGH7.7
  • WatchGuard Firebox logoWatchGuard Firebox
  • cpe:2.3:o:watchguard:fireware
NoYesJul 03, 2026
CVE-2026-13728MEDIUM5.9
  • WatchGuard Firebox logoWatchGuard Firebox
  • cpe:2.3:o:watchguard:fireware
NoYesJul 03, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management