Executive brief
WatchGuard Fireware OS includes a deprecated Mobile Security feature that contains a critical flaw in its endpoint protection manager service. An unauthenticated attacker on the network can exploit this vulnerability to execute arbitrary code on the firewall, potentially compromising the entire security infrastructure protecting the organization and its users.
Technical details
A stack-based buffer overflow exists in the epm (Endpoint Protection Manager) service within the deprecated Mobile Security feature of WatchGuard Fireware OS (CWE-121, CWE-787). The vulnerability also involves use of hard-coded credentials (CWE-798). An unauthenticated remote attacker can trigger this overflow over the network without requiring authentication, allowing arbitrary code execution on the affected appliance. Patches are available: Fireware OS versions 2026.3.1, 2026.2.2, 12.12.2, and 12.5.20 address this vulnerability. WatchGuard reports no known active exploitation.
Affected products
- WatchGuard Fireware OS >=12.0,<12.12.2; >=12.0,<12.5.20 (T15/T35); >=2025.0,<2026.2.2; >=2026.3,<2026.3.1
Timeline
- 2026-08-27: disclosed
- 2026-08-28: advisory
- 2026-08-27: patched: Patches released: Fireware OS 2026.3.1, 2026.2.2, 12.12.2, 12.5.20