Vendor
Watchguard vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 77 vulnerabilities in Watchguard: 1 in the last 7 days and 48 in the last 90 days, 4 of them critical and 4 exploited in the wild. The most recent, CVE-2026-95676, was published on 23 September 2026. 8 technologies have a page of their own.
- Last 7 days
- 1
- Last 90 days
- 48
- Critical, all time
- 4
- Exploited in the wild
- 4
About Watchguard
A provider of network security appliances, secure Wi-Fi, and multi-factor authentication products.
Watchguard technologies
Latest Watchguard vulnerabilities
- CVE-2026-95676: WatchGuard AuthPoint Gateway authentication bypass in LDAP SyncinfoEPSS 0.5%
- CVE-2026-78618: WatchGuard Dimension business logic flaw in backend operationsinfoCVSS 6.9EPSS 0.4%
- CVE-2026-78617: WatchGuard Dimension missing rate-limiting on web logininfoCVSS 6.3EPSS 0.4%
- CVE-2026-78616: WatchGuard Dimension stored XSS in Trusted CA certificate configurationinfoCVSS 4.8EPSS 0.3%
- CVE-2026-78615: WatchGuard Dimension reflected XSS in report detail pageinfoCVSS 4.6EPSS 0.5%
- CVE-2026-78614: WatchGuard Dimension SQL injection in audit report featureinfoCVSS 8.6EPSS 0.7%
- CVE-2026-78613: WatchGuard Dimension SQL injection in log viewerinfoCVSS 8.6EPSS 0.6%
- CVE-2026-78612: WatchGuard Dimension SQL injection in scheduled report featureinfoCVSS 8.6EPSS 0.7%
- CVE-2026-78610: WatchGuard Dimension cross-site request forgery in administrator passphrase changeinfoCVSS 8.4EPSS 0.2%
- CVE-2026-78500: WatchGuard Dimension blind SSRF in database test connectioninfoCVSS 5.1EPSS 0.4%
- CVE-2026-78499: WatchGuard Dimension server-side request forgery via FTP server testinfoCVSS 5.1EPSS 0.4%
- CVE-2026-78498: WatchGuard Dimension server-side request forgery in email server testinfoCVSS 5.1EPSS 0.4%
- CVE-2026-78495: WatchGuard Dimension server-side request forgery in Remote Backup Connection TestinfoCVSS 5.3EPSS 0.4%
- CVE-2026-78174: WatchGuard Dimension exposure of session tokens in diagnostic logsinfoCVSS 9.3EPSS 0.4%
- CVE-2026-78103: WatchGuard Dimension configuration lock bypassinfoCVSS 5.1EPSS 0.5%
- CVE-2026-78047: WatchGuard Dimension stored XSS in task schedulinginfoCVSS 5.1EPSS 0.4%
- CVE-2026-78011: WatchGuard Fireware OS integer underflow in ikedinfoCVSS 8.7EPSS 0.5%
- CVE-2026-78010: WatchGuard Fireware OS stack-based buffer overflow in ikedinfoCVSS 8.7EPSS 0.5%
- CVE-2026-78009: WatchGuard Fireware OS out-of-bounds read in ikedinfoCVSS 8.7EPSS 0.5%
- CVE-2026-78008: WatchGuard Fireware OS buffer overflow in wgagentinfoCVSS 8.6EPSS 0.6%
- CVE-2026-19318: WatchGuard Fireware OS stack buffer overflow in ikedinfoCVSS 9.3EPSS 0.5%
- CVE-2026-19317: WatchGuard Fireware OS out-of-bounds read in ikedinfoCVSS 8.7EPSS 0.3%
- CVE-2026-19316: WatchGuard Fireware OS double-free in iked DoSinfoCVSS 8.7EPSS 0.3%
- CVE-2026-19315: WatchGuard Fireware OS type confusion in iked remote code executioninfoCVSS 9.3EPSS 0.5%
- CVE-2026-19314: WatchGuard Fireware OS integer underflow in ikedinfoCVSS 8.7EPSS 0.3%
Most severe Watchguard vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-9242: WatchGuard Fireware OS out-of-bounds write in iked processcriticalexploited in the wildCVSS 9.8EPSS 73.5%
- CVE-2025-14733: An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated…criticalexploited in the wildCVSS 9.8EPSS 26.5%
- CVE-2022-26318: WatchGuard Firebox and XTM Appliances Arbitrary Code Executioncriticalexploited in the wildCVSS 9.8
- CVE-2022-23176: WatchGuard Firebox and XTM Privilege Escalation Vulnerabilitycriticalexploited in the wildCVSS 8.8
- CVE-2026-6788: WatchGuard Agent uncontrolled search path in WindowshighCVSS 7.8
- CVE-2026-6787: WatchGuard Agent hard-coded cryptographic key in Windows agenthighCVSS 7.8
- CVE-2026-41288: WatchGuard Agent privilege escalation in patch management componenthighCVSS 7.8
- CVE-2025-11838: WatchGuard Fireware OS memory corruption DoS in IKEv2 VPNhighCVSS 7.5EPSS 0.5%
- CVE-2025-1545: WatchGuard Fireware XPath injection in Web CGIhighCVSS 7.5EPSS 0.5%
- CVE-2025-12195: WatchGuard Fireware OS out-of-bounds write in CLIhighCVSS 7.2EPSS 0.7%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 17 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 30 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 1 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/watchguard.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Watchguard vulnerabilities", https://junglewise.ai/threats/vendors/watchguard, 26 September 2026.