Junglewise Threat Intelligence

CVE-2026-78008: WatchGuard Fireware OS buffer overflow in wgagent

CVE-2026-78008 · Severity: info · CVSS 8.6 · Published 2026-08-28

Technologies: Watchguard Fireware OS. Vendors: Watchguard.

Executive brief

WatchGuard Fireware OS is the operating system used in WatchGuard Firebox firewalls, which protect corporate networks by filtering and monitoring network traffic. A buffer overflow vulnerability in the management web interface allows authenticated administrators to disrupt firewall operations or potentially take control of the device by sending specially crafted data, creating a risk to network security and availability.

Technical details

A buffer overflow vulnerability (CWE-787: Out-of-bounds Write) exists in the wgagent component within the WatchGuard Fireware OS Management Web UI. The vulnerability requires authentication as an administrator and network access to the management interface. An attacker with valid admin credentials can exploit this by sending specially crafted network traffic to trigger the out-of-bounds write condition, leading to denial of service or potentially arbitrary code execution on the device. Patches are available in Fireware OS versions 2026.3.1, 2026.2.2, 12.12.2, and 12.5.20.

Affected products

  • WatchGuard Fireware OS Default: >= 2026.3, < 2026.3.1; >= 2025.0, < 2026.2.2; >= 12.0, < 12.12.2. T15/T35: >= 12.0, < 12.5.20

Timeline

  • 2026-08-27: disclosed
  • 2026-08-28: advisory
  • 2026-08-27: patched: Patches released in versions 2026.3.1, 2026.2.2, 12.12.2, and 12.5.20

References

Related threats