Junglewise Threat Intelligence

CVE-2026-13722: WatchGuard Fireware OS firmware validation bypass in backup/restore feature

CVE-2026-13722 · Severity: info · CVSS 8.6 · Published 2026-07-03

Technologies: Watchguard Fireware OS. Vendors: Watchguard.

Executive brief

WatchGuard Fireware OS, the operating system for Firebox network security appliances, contains a flaw in how it handles system backups. An authorized administrator could use this vulnerability to bypass security checks and install unauthorized or malicious firmware on the device. This could lead to a complete compromise of the security appliance, allowing an attacker to maintain persistent access or intercept network traffic.

Technical details

A firmware validation bypass vulnerability (CWE-347) exists in WatchGuard Fireware OS within the backup and restore functionality. The root cause is improper verification of cryptographic signatures when processing backup images that contain firmware updates. An authenticated attacker with administrative privileges can exploit this over the network to upload and execute a tampered or malicious firmware image. This bypasses the standard integrity checks intended to ensure only official WatchGuard software is installed. Patches are available in versions 12.12.1 and 2026.2.1, though some older versions (11.x and 12.5.x) are reported as End of Life or unresolved.

Affected products

  • WatchGuard Fireware OS 11.0 through 11.12.4_Update1, 12.0 through 12.12, 12.5 through 12.5.18, 2025.1 through 2026.2

Timeline

  • 2026-07-02: advisory: WatchGuard published advisory WGSA-2026-00022
  • 2026-07-03: disclosed: CVE-2026-13722 published to NVD

References

Related threats