Junglewise Threat Intelligence

CVE-2026-13053: WatchGuard Fireware OS out-of-bounds write in CLI

CVE-2026-13053 · Severity: info · CVSS 8.6 · Published 2026-07-03

Technologies: Watchguard Fireware OS. Vendors: Watchguard.

Executive brief

A security vulnerability exists in the management interface of WatchGuard Firebox appliances, which are used to protect corporate networks. An authorized administrator could use a specially crafted command to bypass security controls and execute unauthorized code on the device. This could lead to a complete takeover of the firewall, potentially allowing an attacker to disrupt network traffic or access sensitive internal data.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists within the CLI command handler of WatchGuard Fireware OS. The flaw is triggered when a privileged user provides a specially crafted CLI command, leading to memory corruption. While the attack requires high privileges (PR:H), successful exploitation allows for arbitrary code execution with the same permissions as the CLI handler, potentially leading to full system compromise. The vulnerability is addressed in Fireware OS versions 12.12.1 and 2026.2.1, though some older versions (12.5.x on specific hardware) remain unresolved and version 11.x is End of Life.

Affected products

  • WatchGuard Fireware OS 11.0 through 11.12.4_Update1, 12.0 through 12.12, 12.5 through 12.5.18, 2025.1 through 2026.2

Timeline

  • 2026-07-02: advisory: WatchGuard published advisory WGSA-2026-00030
  • 2026-07-03: disclosed: NVD publication date

References

Related threats