Junglewise Threat Intelligence

CVE-2026-4315: WatchGuard Fireware OS CSRF in WebUI

CVE-2026-4315 · Severity: medium · CVSS 6.5 · Published 2026-03-30

Technologies: Watchguard Fireware OS. Vendors: Watchguard.

Executive brief

WatchGuard Fireware OS is the operating system powering WatchGuard Firebox network firewalls, which protect corporate networks from external threats. A cross-site request forgery (CSRF) vulnerability in the WebUI administrative interface allows an attacker to trick authenticated administrators into visiting a malicious web page, which can trigger a denial-of-service condition that disrupts firewall management capabilities and potentially impacts network security operations.

Technical details

This is a CSRF vulnerability (CWE-352) in the WatchGuard Fireware OS WebUI that allows an unauthenticated remote attacker to forge requests on behalf of an authenticated administrator. The attack requires social engineering—an administrator must be convinced to visit an attacker-controlled web page while logged into the Fireware WebUI. When successful, the forged request can trigger a denial-of-service condition in the web interface. The vulnerability affects Fireware OS versions in the 2025.1–2026.1, 12.0–12.11, and 11.8–11.12.4 branches, with patches available in versions 2026.2, 12.12, and platform-specific releases (12.5.18 for T15/T35, 12.11.9 for EUCC). No exploitation in the wild has been reported.

Affected products

  • WatchGuard Fireware OS 2025.1 through 2026.1, 12.0 through 12.11.4+541730, 11.8 through 11.12.4+541730

Timeline

  • 2026-03-30: disclosed: CVE published
  • 2026-03-30: patched: Patches released in Fireware OS 2026.2, 12.12, 12.5.18, 12.11.9
  • 2026-08-27: other: Advisory updated with additional detail

References

Related threats