Junglewise Threat Intelligence

CVE-2026-4266: WatchGuard Fireware OS insecure deserialization in Access Portal

CVE-2026-4266 · Severity: medium · CVSS 6.7 · Published 2026-03-30

Technologies: Watchguard Fireware OS. Vendors: Watchguard.

Executive brief

WatchGuard Fireware OS runs a web-based access portal on network firewalls that allows employees to securely connect to corporate networks. A flaw in how the portal processes data allows an attacker who has already gained write access to the firewall's filesystem (through another separate vulnerability) to execute arbitrary code with portal-level privileges, potentially compromising network security and user access controls.

Technical details

The vulnerability is an insecure deserialization flaw (CWE-502) in the WatchGuard Fireware OS Access Portal component that processes serialized data without proper validation. An attacker who has obtained write access to the local filesystem through a separate vulnerability can craft malicious serialized objects and place them where the portal code deserializes them, leading to arbitrary code execution in the context of the portald user. The vulnerability requires prior filesystem write access and does not affect Firebox T15 and T35 platforms that lack the Access Portal feature. Patched versions are available: Fireware OS 2026.2 or 12.12 for Default platforms, and 12.11.9 for EUCC systems.

Affected products

  • WatchGuard Fireware OS Default >= 2025.1, < 2026.2, >= 12.1, < 12.12; EUCC >= 12.1, < 12.11.9

Timeline

  • 2026-03-30: disclosed
  • 2026-03-30: patched: Fireware OS 2026.2, 12.12, and 12.11.9 available

References

Related threats