Junglewise Threat Intelligence

CVE-2026-13050: WatchGuard Fireware OS out-of-bounds write in networkd

CVE-2026-13050 · Severity: info · CVSS 8.6 · Published 2026-07-03

Technologies: Watchguard Fireware OS, Watchguard Fireware. Vendors: Watchguard.

Executive brief

WatchGuard Fireware OS is the operating system used by Firebox network security appliances to protect corporate networks. A vulnerability in the system's networking process could allow an administrator with existing login credentials to take full control of the device. If exploited, an attacker could execute unauthorized commands, potentially leading to network disruption or unauthorized access to internal traffic.

Technical details

An out-of-bounds (OOB) write vulnerability (CWE-787) exists within the 'networkd' process of WatchGuard Fireware OS. The flaw is reachable via specially crafted requests sent to the Management Web UI. While the attack vector is network-based, exploitation requires high privileges (authenticated privileged user). Successful exploitation allows for arbitrary code execution on the underlying appliance. Patches are available in versions 12.12.1 and 2026.2.1, though some older branches like 12.5.x remain unresolved or are End-of-Life.

Affected products

  • WatchGuard Fireware OS 11.0 - 11.12.4_Update1, 12.0 - 12.12, 12.5 - 12.5.18, 2025.1 - 2026.2

Timeline

  • 2026-07-02: advisory: WatchGuard published advisory WGSA-2026-00029
  • 2026-07-03: disclosed: CVE published to NVD dataset

References

Related threats