Junglewise Threat Intelligence

CVE-2026-13374: WatchGuard Fireware OS Stored XSS in ConnectWise Integration module

CVE-2026-13374 · Severity: info · CVSS 4.8 · Published 2026-07-03

Technologies: Watchguard Fireware OS. Vendors: Watchguard.

Executive brief

A security vulnerability exists in the ConnectWise integration module of WatchGuard Fireware OS, which is used to manage network security appliances. An attacker with high-level administrative privileges could inject malicious scripts into the management interface. If another administrator views the affected page, the script could execute, potentially leading to unauthorized actions or session hijacking within the management console.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the ConnectWise Technology Integration module of WatchGuard Fireware OS due to improper neutralization of input during web page generation. The vulnerability is reachable over the network but requires high-privileged (PR:H) credentials and some user interaction (UI:P) from another administrator. An attacker can exploit this to inject malicious scripts that execute in the context of a victim's browser session when they navigate to the affected configuration page. This issue represents an additional attack path for the previously identified CVE-2025-13937. Patches are available in versions 12.12.1 and 2026.2.1.

Affected products

  • WatchGuard Fireware OS (ConnectWise Technology Integration module) 12.4 to 12.12, 12.5 to 12.5.18, 2025.1 to 2026.2

Timeline

  • 2026-07-02: advisory: WatchGuard published advisory WGSA-2026-00015
  • 2026-07-03: disclosed: CVE published to NVD dataset

References

Related threats