Network security

WatchGuard advisories: every record the registers tie to its products

In one line

58 advisories are attributed to WatchGuard products in this record, covering March 2022 to July 2026, and 4 of them appear in the CISA catalogue of known exploited vulnerabilities. A further 0 register entries mention WatchGuard without naming one of its products as affected, and are excluded rather than counted. Each entry below links to the register that published it.

Attributed

58

tied to a named product

Known exploited

4

in the CISA catalogue

Rated critical

6

by the register

Last checked

Jul 18, 2026

sources re-queried

Why this list is shorter than a CVE mirror

The registers are searched by keyword, so a search for a company name returns advisories that merely mention it. A mirror publishes those. This page does not: an entry appears only when the register itself ties it to a product of WatchGuard, through a reference on the vendor's own domain, the vendor named as the assigning authority, or the affected product list naming it.

0 entries did not clear that bar and are not shown. That is the difference, and it is deliberate: a page that lists another company's vulnerability under this heading is wrong in the way that matters most.

56 of the 58 records carry a CVSS base score from the register. Where none is published, none is shown, and no score is estimated.

The full list, most recently exploited and most recent first

Records held by several registers are folded into one entry with a link to each, so the same vulnerability is not counted twice. Entries listed in the CISA catalogue of known exploited vulnerabilities are shown first, because that is the one flag on this page that changes what a reader should do next.

  • CVE-2025-14733criticalCVSS 9.3Known exploitedDec 19, 2025

    WatchGuard Firebox Out of Bounds Write Vulnerability

  • CVE-2025-9242criticalCVSS 9.3Known exploitedNov 12, 2025

    WatchGuard Firebox Out-of-Bounds Write Vulnerability

  • CVE-2022-23176criticalKnown exploitedApr 11, 2022

    WatchGuard Firebox and XTM Privilege Escalation Vulnerability

  • CVE-2022-26318criticalKnown exploitedMar 25, 2022

    WatchGuard Firebox and XTM Appliances Arbitrary Code Execution

  • WID-SEC-2026-2193highCVSS 8.1Jul 03, 2026

    Affected products: WatchGuard Firebox

  • CVE-2026-13053highCVSS 8.6Jul 02, 2026

    An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command.

  • CVE-2026-13050highCVSS 8.6Jul 02, 2026

    An Out-of-bounds Write vulnerability in WatchGuard Fireware OS networkd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to…

  • CVE-2026-13054highCVSS 8.6Jul 02, 2026

    A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated attacker to write arbitrary files on the Firebox's filesystem.

  • CVE-2026-13079highCVSS 7.3Jul 02, 2026

    A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows allows a local attacker to escalate their privileges to NT AUTHORITY\SYSTEM on the…

  • CVE-2026-8247highCVSS 7.7Jul 02, 2026

    An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker on the same local network segment to execute arbitrary code.

  • CVE-2026-13728mediumCVSS 5.9Jul 02, 2026

    In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved credentials for Access Portal resources.

  • CVE-2026-13084highCVSS 8.7Jul 02, 2026

    A null pointer dereference vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to create a denial-of-service (DoS) condition by sending specially crafted…

  • CVE-2026-13368criticalCVSS 9.2Jul 02, 2026

    WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2.

  • CVE-2026-13722highCVSS 8.6Jul 02, 2026

    WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image via the backup/restore feature.

  • CVE-2026-13384highCVSS 8.6Jul 02, 2026

    An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the…

  • CVE-2026-13383highCVSS 8.6Jul 02, 2026

    An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to…

  • CVE-2026-13377mediumCVSS 4.8Jul 02, 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS SIP Proxy module allows Stored XSS.

  • CVE-2026-13376mediumCVSS 4.8Jul 02, 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS spamBlocker module allows Stored XSS.

  • CVE-2026-13375mediumCVSS 4.8Jul 02, 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Autotask Technology Integration module) allows Stored…

  • CVE-2026-13374mediumCVSS 4.8Jul 02, 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (ConnectWise Technology Integration module) allows Stored…

  • CVE-2026-13373mediumCVSS 4.8Jul 02, 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Tigerpaw Technology Integration module) allows Stored…

  • CVE-2026-13371mediumCVSS 6.9Jul 02, 2026

    An authenticated administrator can trigger a denial-of-service condition in the Fireware Management Web UI by sending malformed or crafted data to the put_data endpoint, which performs…

  • CVE-2026-6788highCVSS 8.5May 06, 2026

    Uncontrolled Search Path Element vulnerability in WatchGuard Agent on Windows allows Using Malicious Files.This issue affects WatchGuard Agent before 1.25.03.0000.

  • CVE-2026-6787highCVSS 8.5May 06, 2026

    Use of Hard-coded Cryptographic Key vulnerability in WatchGuard Agent on Windows allows Inclusion of Code in Existing Process.This issue affects WatchGuard Agent: before 1.25.03.0000.

  • CVE-2026-41286highCVSS 7.1May 06, 2026

    Stack-based Buffer Overflow vulnerability in the WatchGuard Agent discovery service on Windows allows Overflow Buffers.

  • CVE-2026-41288highCVSS 7.3May 06, 2026

    Incorrect permission assignment for a resource in the patch management component of the WatchGuard Agent on Windows allows an authenticated local user to elevate their privileges to NT…

  • CVE-2026-41287highCVSS 7.1May 06, 2026

    Stack-based Buffer Overflow vulnerability in the WatchGuard Agent discovery service on Windows allows Overflow Buffers.

  • WID-SEC-2026-0952mediumCVSS 7.2Apr 02, 2026

    Affected products: WatchGuard Firebox

  • CVE-2026-3987highCVSS 8.6Apr 01, 2026

    A path traversal vulnerability in the Fireware OS Web UI on WatchGuard Firebox systems may allow a privileged authenticated remote attacker to execute arbitrary code in the context of an…

  • WID-SEC-2026-0892mediumCVSS 6.7Mar 31, 2026

    Affected products: WatchGuard Firebox

  • CVE-2026-4315highCVSS 7.1Mar 30, 2026

    A Cross-Site Request Forgery (CSRF) vulnerability in the WatchGuard Fireware OS WebUI could allow a remote attacker to trigger a denial-of-service (DoS) condition in the Fireware Web UI by…

  • CVE-2026-4266highCVSS 8.4Mar 30, 2026

    An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to the local filesystem through another vulnerability to execute…

  • WID-SEC-2026-0570mediumCVSS 7.2Mar 04, 2026

    Affected products: WatchGuard Firebox

  • CVE-2026-3344mediumCVSS 6.9Mar 03, 2026

    A vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fireware OS filesystem integrity check and maintain limited persistence via a maliciously-crafted firmware…

  • CVE-2026-3343mediumCVSS 5.1Mar 03, 2026

    A reflected cross-site scripting (XSS) vulnerability in the Fireware OS Web UI enabled execution of malicious JavaScript in the context of an authenticated management user's browser when…

  • CVE-2026-3342highCVSS 8.6Mar 03, 2026

    An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an authenticated privileged administrator to execute arbitrary code with root permissions via an exposed management…

  • WID-SEC-2026-0263highCVSS 10.0Feb 02, 2026

    Affected products: WatchGuard Firebox

  • CVE-2026-1498highCVSS 7.0Jan 30, 2026

    An LDAP Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensitive information from a connected LDAP authentication server through…

  • WID-SEC-2025-2902criticalCVSS 9.8Dec 19, 2025

    Affected products: WatchGuard Firebox

  • WID-SEC-2025-2749mediumCVSS 7.5Dec 05, 2025

    Affected products: WatchGuard Firebox

  • WID-SEC-2025-1528highCVSS 9.1Dec 05, 2025

    Affected products: WatchGuard Firebox

  • CVE-2025-1547highCVSS 7.5Dec 04, 2025

    A stack-based buffer overflow vulnerability [CWE-121] in WatchGuard Fireware OS's certificate request command could allow an authenticated privileged user to execute arbitrary code via…

  • CVE-2025-1910mediumCVSS 6.3Dec 04, 2025

    The WatchGuard Mobile VPN with SSL Client on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY/SYSTEM on the Windows…

  • CVE-2025-11838highCVSS 8.7Dec 04, 2025

    A memory corruption vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker to trigger a Denial of Service (DoS) condition in the Mobile User VPN with IKEv2 and the…

  • CVE-2025-13938mediumCVSS 4.8Dec 04, 2025

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Autotask Technology Integration module) allows Stored…

  • CVE-2025-13937mediumCVSS 4.8Dec 04, 2025

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (ConnectWise Technology Integration module) allows Stored…

  • CVE-2025-13936mediumCVSS 4.8Dec 04, 2025

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Tigerpaw Technology Integration module) allows Stored…

  • CVE-2025-12196highCVSS 8.6Dec 04, 2025

    An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command.This…

  • CVE-2025-12195highCVSS 8.6Dec 04, 2025

    An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via specially crafted IPSec configuration CLI…

  • CVE-2025-12026highCVSS 8.6Dec 04, 2025

    An Out-of-bounds Write vulnerability in WatchGuard Fireware OS’s certificate request command could allow an authenticated privileged user to execute arbitrary code via specially crafted CLI…

  • WID-SEC-2025-2071highCVSS 9.8Nov 13, 2025

    Affected products: WatchGuard Firebox

  • CVE-2025-1549mediumCVSS 6.3Oct 29, 2025

    A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands with elevated privileges on the Windows…

  • CVE-2025-4106highCVSS 8.9Oct 24, 2025

    An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by uploading a platform and version-specific…

  • WID-SEC-2025-1090mediumCVSS 4.8May 19, 2025

    Affected products: WatchGuard Firebox

  • WID-SEC-2025-0376mediumCVSS 4.7Feb 14, 2025

    Affected products: WatchGuard Firebox

  • WID-SEC-2024-1477mediumCVSS 7.2Jun 28, 2024

    Affected products: WatchGuard Firebox

  • WID-SEC-2022-0455highCVSS 9.8Jun 24, 2022

    Affected products: WatchGuard Firebox

  • WID-SEC-2022-0188highCVSS 9.1Jun 08, 2022

    Affected products: WatchGuard Firebox

Which registers contributed

RegisterOperated byEntriesLatest
European Vulnerability DatabaseENISA, European Union42Jul 02, 2026
CERT-Bund security advisoriesBSI, Federal Republic of Germany14Jul 03, 2026
Known Exploited Vulnerabilities catalogueCISA, United States4Dec 19, 2025

The entry counts here are the raw register totals for WatchGuard, before attribution. They are larger than the list above for exactly that reason.

Questions this page answers

How many vulnerabilities does WatchGuard have?

58 advisories in this record are tied by a register to a product of WatchGuard. That is not the same as the number of vulnerabilities the products contain, and no public source knows that number. It is the count of what has been found, disclosed and published, which depends on how much the products are examined and how openly the vendor discloses.

Are any WatchGuard vulnerabilities being actively exploited?

4 of the 58 records here appear in the CISA catalogue of known exploited vulnerabilities, which lists flaws with confirmed exploitation in the wild. They are shown first in the list above. Whether any of them affects your deployment depends on the versions and components you run.

Why does this page show fewer CVEs for WatchGuard than other sites?

Because a keyword search for a company name returns advisories about other companies' products that mention it in passing, and this page excludes those. 0 register entries name WatchGuard without naming one of its products as affected. A mirror that lists them produces a longer page and a wrong number.

Where do the WatchGuard advisories on this page come from?

From European Vulnerability Database (ENISA, European Union); CERT-Bund security advisories (BSI, Federal Republic of Germany); Known Exploited Vulnerabilities catalogue (CISA, United States). Every entry links back to the register that published it, and carries the date that register states. Where the same vulnerability is held by several registers it is shown once with a link to each, rather than counted twice.

Does a long advisory list mean WatchGuard is insecure?

No. A register records what researchers found and what the vendor disclosed, so a widely deployed product with a working disclosure process accumulates more entries than one nobody examines. A short list can equally mean a small install base or a vendor that publishes little. This page reports the record and does not rate the vendor, because whether this is acceptable depends on your risk appetite, your compliance scope and the alternatives you are weighing.

A list of advisories is not a risk assessment

What matters is which of these touch the components you actually run, in the configuration you actually run them in, and whether that is acceptable next to the alternatives on your shortlist. DecisionOS reads the same pool against the criteria of a real decision and produces a memo that holds up in front of a board and an auditor.

The full WatchGuard record, including sources and open questions

WatchGuard vulnerabilities: all 58 advisories on record, with sources | DecisionOS by nexalign