Technology · Watchguard
Watchguard Fireware OS vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 45 vulnerabilities in Watchguard Fireware OS: 0 in the last 7 days and 28 in the last 90 days, 1 of them critical and 1 exploited in the wild. The most recent, CVE-2026-78011, was published on 28 August 2026.
- Last 7 days
- 0
- Last 90 days
- 28
- Critical, all time
- 1
- Exploited in the wild
- 1
About Watchguard Fireware OS
Fireware OS is the operating system designed for WatchGuard Firebox security appliances.
Latest Watchguard Fireware OS vulnerabilities
- CVE-2026-78011: WatchGuard Fireware OS integer underflow in ikedinfoCVSS 8.7EPSS 0.5%
- CVE-2026-78010: WatchGuard Fireware OS stack-based buffer overflow in ikedinfoCVSS 8.7EPSS 0.5%
- CVE-2026-78009: WatchGuard Fireware OS out-of-bounds read in ikedinfoCVSS 8.7EPSS 0.5%
- CVE-2026-78008: WatchGuard Fireware OS buffer overflow in wgagentinfoCVSS 8.6EPSS 0.6%
- CVE-2026-19318: WatchGuard Fireware OS stack buffer overflow in ikedinfoCVSS 9.3EPSS 0.5%
- CVE-2026-19317: WatchGuard Fireware OS out-of-bounds read in ikedinfoCVSS 8.7EPSS 0.3%
- CVE-2026-19316: WatchGuard Fireware OS double-free in iked DoSinfoCVSS 8.7EPSS 0.3%
- CVE-2026-19315: WatchGuard Fireware OS type confusion in iked remote code executioninfoCVSS 9.3EPSS 0.5%
- CVE-2026-19314: WatchGuard Fireware OS integer underflow in ikedinfoCVSS 8.7EPSS 0.3%
- CVE-2026-19313: WatchGuard Fireware OS heap overflow in ikedinfoCVSS 9.3EPSS 0.5%
- CVE-2026-13086: WatchGuard Fireware OS stack buffer overflow in Mobile Security epminfoCVSS 9.3EPSS 0.4%
- CVE-2026-81851: WatchGuard Fireware OS heap buffer overflow in ikedinfoCVSS 6.9EPSS 0.4%
- CVE-2026-8247: WatchGuard Fireware OS out-of-bounds write in admdinfoCVSS 7.7
- CVE-2026-13728: WatchGuard Fireware OS hard-coded encryption key in FireCluster Access PortalinfoCVSS 5.9
- CVE-2026-13722: WatchGuard Fireware OS firmware validation bypass in backup/restore featureinfoCVSS 8.6
- CVE-2026-13384: WatchGuard Fireware OS out-of-bounds write in wgagentinfoCVSS 8.6
- CVE-2026-13383: WatchGuard Fireware OS out-of-bounds write in ikestubdinfoCVSS 8.6
- CVE-2026-13377: WatchGuard Fireware OS stored XSS in SIP ProxyinfoCVSS 4.8
- CVE-2026-13376: WatchGuard Fireware OS stored XSS in spamBlocker moduleinfoCVSS 4.8
- CVE-2026-13375: WatchGuard Fireware OS stored XSS in Autotask Technology IntegrationinfoCVSS 4.8
- CVE-2026-13374: WatchGuard Fireware OS Stored XSS in ConnectWise Integration moduleinfoCVSS 4.8
- CVE-2026-13373: WatchGuard Fireware OS Stored XSS in Tigerpaw Technology IntegrationinfoCVSS 4.8
- CVE-2026-13371: WatchGuard Fireware OS denial of service in Management Web UIinfoCVSS 6.9
- CVE-2026-13368: WatchGuard Fireware OS use-after-free in Mobile VPN IKEv2 LDAP authinfoCVSS 9.2
- CVE-2026-13084: WatchGuard Fireware OS DoS via NULL pointer dereference in ikedinfoCVSS 8.7
Most severe Watchguard Fireware OS vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-9242: WatchGuard Fireware OS out-of-bounds write in iked processcriticalexploited in the wildCVSS 9.8EPSS 73.5%
- CVE-2025-11838: WatchGuard Fireware OS memory corruption DoS in IKEv2 VPNhighCVSS 7.5EPSS 0.5%
- CVE-2025-1545: WatchGuard Fireware XPath injection in Web CGIhighCVSS 7.5EPSS 0.5%
- CVE-2025-12195: WatchGuard Fireware OS out-of-bounds write in CLIhighCVSS 7.2EPSS 0.7%
- CVE-2025-12196: WatchGuard Fireware OS out-of-bounds write in CLI ping commandhighCVSS 7.2EPSS 0.6%
- CVE-2025-12026: WatchGuard Fireware OS out-of-bounds write in certdhighCVSS 7.2EPSS 0.4%
- CVE-2025-1547: WatchGuard Fireware OS stack overflow in certificate request commandhighCVSS 7.2EPSS 0.4%
- CVE-2026-4266: WatchGuard Fireware OS insecure deserialization in Access PortalmediumCVSS 6.7EPSS 0.4%
- CVE-2026-4315: WatchGuard Fireware OS CSRF in WebUImediumCVSS 6.5EPSS 0.2%
- CVE-2026-3343: WatchGuard Fireware OS reflected XSS in Web UImediumCVSS 6.1EPSS 0.3%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 16 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 12 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/fireware-os.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Watchguard Fireware OS vulnerabilities", https://junglewise.ai/threats/technologies/fireware-os, 26 September 2026.