
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-13728 is a hard-coded encryption key vulnerability (CWE-798) in WatchGuard Fireware OS affecting FireCluster deployments with the Access Portal feature enabled. Under certain exception circumstances, the OS may use a static, hard-coded encryption key to encrypt saved credentials for Access Portal resources, allowing those credentials to be decrypted by an attacker. The vulnerability affects Fireware OS versions 12.1 through 12.12 and 2025.1 through 2026.2; standalone Fireboxes and devices without Access Portal support are not affected. It carries a CVSS v3.1 base score of 4.4 (Medium) and a CVSS v4.0 base score of 5.9 (Medium) (GitHub Advisory, WatchGuard Advisory).
The root cause is classified as CWE-798 (Use of Hard-coded Credentials): in exception circumstances during FireCluster operation, Fireware OS falls back to a static, embedded encryption key rather than a dynamically generated one to protect Access Portal resource credentials at rest. An attacker who can access the encrypted credential store — either through network access to the FireCluster management interface or by obtaining a copy of the stored credential data — can apply the known hard-coded key to decrypt the credentials without any brute-force effort. Exploitation requires high privileges and the presence of specific deployment conditions (FireCluster with Access Portal enabled), limiting the attack surface but not eliminating the risk (GitHub Advisory, WatchGuard Advisory).
Successful exploitation results in a high confidentiality impact: an attacker can decrypt and retrieve plaintext credentials stored for Access Portal resources, which may include usernames and passwords for backend systems, web applications, or internal services accessible through the portal. There is no integrity or availability impact directly from this vulnerability. However, recovered credentials could enable lateral movement into systems protected by the Access Portal, potentially expanding the attacker's foothold beyond the Firebox itself (GitHub Advisory, WatchGuard Advisory).
As of the time of publication, there is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.134% (3rd percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. NVD SSVC assessment classifies exploitation as "none" and the vulnerability as non-automatable, reflecting the high-privilege and specific deployment preconditions required (WatchGuard Advisory).
WatchGuard has released patched versions of Fireware OS: upgrade to version 12.12.1 or later (for the 12.x branch) or to version 2026.2.1 or later (for the 2025.x/2026.x branch) to remediate this vulnerability (WatchGuard Advisory). Organizations should verify whether their deployment uses a FireCluster with Access Portal enabled, as standalone Fireboxes and devices without Access Portal support are not affected. As an interim measure, restrict network access to FireCluster management interfaces to trusted administrative hosts only, and review and rotate any credentials stored in the Access Portal after upgrading.
The vulnerability was disclosed by WatchGuard via their PSIRT advisory (WGSA-2026-00025) and published to the GitHub Advisory Database on July 3, 2026. Coverage has been limited to automated vulnerability tracking feeds and aggregators such as CVEfeed.io, Vulners, and CIRCL, with no notable independent researcher commentary or significant social media discussion identified at this time (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."