Junglewise Threat Intelligence

CVE-2026-3343: WatchGuard Fireware OS reflected XSS in Web UI

CVE-2026-3343 · Severity: medium · CVSS 6.1 · Published 2026-03-03

Technologies: Watchguard Fireware OS. Vendors: Watchguard.

Executive brief

WatchGuard Fireware OS is a firewall platform used to secure corporate networks. A reflected cross-site scripting (XSS) vulnerability in the Web UI management interface allows an attacker to inject malicious JavaScript code that executes in an administrator's browser when they click a specially crafted link. This could lead to unauthorized configuration changes, credential theft, or system compromise under the attacker's control.

Technical details

This is a reflected cross-site scripting (CWE-79) vulnerability in the Fireware OS Web UI that fails to properly neutralize user-supplied input during web page generation. The vulnerability requires an authenticated management user to click on a specially crafted malicious link, but does not require prior authentication from the attacker. Once clicked, arbitrary JavaScript executes in the context of the authenticated user's browser session, potentially allowing session hijacking, admin action abuse, or credential exfiltration. Patches are available: Fireware OS 2026.1.2 and 12.11.8 or later resolve this issue.

Affected products

  • WatchGuard Fireware OS 2025.1 to 2026.1.1, 12.7 to 12.11.7

Timeline

  • 2026-03-03: disclosed
  • 2026-03-03: patched: Patches released: Fireware OS 2026.1.2 and 12.11.8

References

Related threats