Executive brief
WatchGuard Fireware OS runs a web-based access portal on network firewalls that allows employees to securely connect to corporate networks. A flaw in how the portal processes data allows an attacker who has already gained write access to the firewall's filesystem (through another separate vulnerability) to execute arbitrary code with portal-level privileges, potentially compromising network security and user access controls.
Technical details
The vulnerability is an insecure deserialization flaw (CWE-502) in the WatchGuard Fireware OS Access Portal component that processes serialized data without proper validation. An attacker who has obtained write access to the local filesystem through a separate vulnerability can craft malicious serialized objects and place them where the portal code deserializes them, leading to arbitrary code execution in the context of the portald user. The vulnerability requires prior filesystem write access and does not affect Firebox T15 and T35 platforms that lack the Access Portal feature. Patched versions are available: Fireware OS 2026.2 or 12.12 for Default platforms, and 12.11.9 for EUCC systems.
Affected products
- WatchGuard Fireware OS Default >= 2025.1, < 2026.2, >= 12.1, < 12.12; EUCC >= 12.1, < 12.11.9
Timeline
- 2026-03-30: disclosed
- 2026-03-30: patched: Fireware OS 2026.2, 12.12, and 12.11.9 available