WatchGuard Firebox admd Out of Bounds Write Vulnerability
Summary
| CVE | CVE-2026-8247 |
|---|---|
| State | PUBLISHED |
| Assigner | WatchGuard |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-03 00:16:52 UTC |
| Updated | 2026-08-14 12:53:37 UTC |
| Description | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker on the same local network segment to execute arbitrary code. This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2. |
Risk And Classification
Primary CVSS: v4.0 7.7 HIGH from 5d1c2695-1a31-4499-88ae-e847036fd7e3
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.002060000 probability, percentile 0.108130000 (date 2026-08-11)
Problem Types: CWE-120 | CWE-787 | CWE-120 CWE-120
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | 5d1c2695-1a31-4499-88ae-e847036fd7e3 | Secondary | 7.7 | HIGH | CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | DECLARED | 7.7 | HIGH | CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| 3.1 | [email protected] | Primary | 8.8 | HIGH | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
CVSS v4.0 Breakdown
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1 Breakdown
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Watchguard | Fireware | All | All | All | All |
| Operating System | Watchguard | Fireware | 11.12.4 | - | All | All |
| Operating System | Watchguard | Fireware | 11.12.4 | u1 | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | WatchGuard | Fireware OS | affected 2025.1 2026.2.1 custom | Default |
| CNA | WatchGuard | Fireware OS | affected 12.0 12.12.1 custom | Default |
| CNA | WatchGuard | Fireware OS | affected 11.0 * custom | Default |
| CNA | WatchGuard | Fireware OS | affected 12.0 12.5.19 custom | T15/T35 |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00026 | 5d1c2695-1a31-4499-88ae-e847036fd7e3 | www.watchguard.com | Vendor Advisory |
| psirt.watchguard.com/CVE-2026-8247 | 5d1c2695-1a31-4499-88ae-e847036fd7e3 | psirt.watchguard.com | Broken Link |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Xander Mackenzie | @thetrueartist working with TrendAI Zero Day Initiative (en)
Additional Advisory Data
Solutions
CNA: Fireware OS 2026.2.1, Fireware OS 12.12.1, Fireware OS 12.5.19
Exploits
CNA: WatchGuard is not aware of any exploitation of this vulnerability in the wild.