Known Vulnerabilities for products from Watchguard

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Watchguard".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Additional devices specifications by Watchguard can be found at device.report : Watchguard

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-41288 json Not Provided 2026-05-06 2026-08-10
CVE-2026-41287 json Not Provided 2026-05-06 2026-08-10
CVE-2026-41286 json Stack-based Buffer Overflow vulnerability in the WatchGuard Agent discovery service on Windows allows Overflow Buffers. An un... Not Provided 2026-05-06 2026-08-10
CVE-2026-13728 json In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved cred... Not Provided 2026-07-03 2026-08-10
CVE-2026-13722 json WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image via the backup/restore feature. A... Not Provided 2026-07-03 2026-08-14
CVE-2026-13384 json Not Provided 2026-07-03 2026-08-10
CVE-2026-13383 json An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authenticated privileged user ... Not Provided 2026-07-03 2026-08-10
CVE-2026-13377 json Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Firew... Not Provided 2026-07-03 2026-08-10
CVE-2026-13376 json Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Firew... Not Provided 2026-07-03 2026-08-10
CVE-2026-13375 json Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Firew... Not Provided 2026-07-03 2026-08-10
CVE-2026-13374 json Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Firew... Not Provided 2026-07-03 2026-08-10
CVE-2026-13373 json Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Firew... Not Provided 2026-07-03 2026-08-10
CVE-2026-13371 json An authenticated administrator can trigger a denial-of-service condition in the Fireware Management Web UI by sending malform... Not Provided 2026-07-03 2026-08-14
CVE-2026-13368 json WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mob... Not Provided 2026-07-03 2026-08-14
CVE-2026-13084 json A null pointer dereference vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to create a de... Not Provided 2026-07-03 2026-08-14
CVE-2026-13079 json A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows allows a local attacker t... Not Provided 2026-07-03 2026-08-10
CVE-2026-13054 json A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated attacker to ... Not Provided 2026-07-03 2026-08-10
CVE-2026-13053 json An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute ... Not Provided 2026-07-03 2026-08-10
CVE-2026-13050 json An Out-of-bounds Write vulnerability in WatchGuard Fireware OS networkd process could allow an authenticated privileged user ... Not Provided 2026-07-03 2026-08-14
CVE-2026-8247 json An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker on the same local networ... Not Provided 2026-07-03 2026-08-14

Known software with vulnerabilities from Watchguard

Type Vendor Product Version
Operating
System
WatchguardAd Helper Firmware5.8.5.10317
Operating
System
WatchguardFireware11.0.2
ApplicationWatchguardFireware Xtm11.8.3
ApplicationWatchguardHawkeye G3.0.1.4912
ApplicationWatchguardRapidstream-
ApplicationWatchguardServer Center11.7.3
ApplicationWatchguardWatchguard System Manager-
ApplicationWatchguardXcs10.0
HardwareWatchguardXmt515-
Operating
System
WatchguardXmt515 Firmware-

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report