Junglewise Threat Intelligence

CVE-2026-13377: WatchGuard Fireware OS stored XSS in SIP Proxy

CVE-2026-13377 · Severity: info · CVSS 4.8 · Published 2026-07-03

Technologies: Watchguard Fireware OS. Vendors: Watchguard.

Executive brief

A security vulnerability exists in the SIP Proxy module of WatchGuard Firebox firewalls, which are used to protect and manage corporate network traffic. An attacker with high-level administrative privileges could inject malicious scripts into the device's configuration interface. If another administrator views the affected settings, the script could execute, potentially leading to unauthorized actions or session hijacking within the management console.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the SIP Proxy module of WatchGuard Fireware OS due to improper neutralization of input during web page generation. The flaw is tracked as an additional attack path for a previously identified issue. An attacker requires high privileges (PR:H) to inject the malicious payload into the configuration. The exploit is triggered when a user with administrative access interacts with the affected management page. The vulnerability affects multiple versions of Fireware OS, including the 12.x and 2025.x branches. Patches have been released in versions 12.12.1 and 2026.2.1, though some older hardware models (T15/T35) remain unresolved.

Affected products

  • WatchGuard Fireware OS 12.0 to 12.12, 12.5 to 12.5.18, 2025.1 to 2026.2

Timeline

  • 2026-07-02: advisory
  • 2026-07-02: disclosed
  • 2026-07-02: patched

References

Related threats