Junglewise Threat Intelligence

CVE-2026-13376: WatchGuard Fireware OS stored XSS in spamBlocker module

CVE-2026-13376 · Severity: info · CVSS 4.8 · Published 2026-07-03

Technologies: Watchguard Fireware OS. Vendors: Watchguard.

Executive brief

WatchGuard Fireware OS is the operating system used to manage Firebox network security appliances. A security flaw in the spamBlocker module could allow an attacker with high-level administrative privileges to inject malicious scripts into the management interface. If another administrator views the affected page, the script could execute in their browser, potentially leading to unauthorized actions or session hijacking within the management console.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the spamBlocker module of WatchGuard Fireware OS due to improper neutralization of input during web page generation. The vulnerability requires high-privileged administrative access (PR:H) and some user interaction (UI:P) from another administrator to be triggered. An attacker can exploit this to inject malicious JavaScript into the Firebox management interface, which could lead to session hijacking or unauthorized configuration changes. This issue represents an additional attack path for a previously identified vulnerability (CVE-2025-1071). Patches are available in versions 12.12.1 and 2026.2.1, though some legacy models (T15/T35) remain unresolved.

Affected products

  • WatchGuard Fireware OS 12.0 through 12.12, 12.5 through 12.5.18, 2025.1 through 2026.2

Timeline

  • 2026-07-02: advisory: WatchGuard published the security advisory WGSA-2026-00018.
  • 2026-07-03: disclosed: CVE-2026-13376 was published to the NVD.

References

Related threats