<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/">
  <channel>
    <title>WatchGuard CVEs · CVE Brief</title>
    <link>https://cvebrief.com/archive/cves/vendor/watchguard/</link>
    <atom:link href="https://cvebrief.com/feeds/vendor/watchguard.xml" rel="self" type="application/rss+xml"/>
    <description>High and critical WatchGuard vulnerabilities covered by CVE Brief, with independent analyst commentary.</description>
    <language>en-us</language>
    <lastBuildDate>Fri, 28 Aug 2026 12:00:00 GMT</lastBuildDate>
    <item>
      <title>CVE-2026-13108 · CVSS 8.7 · Dimension</title>
      <link>https://cvebrief.com/cve/cve-2026-13108/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-watchguard-CVE-2026-13108</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/watchguard.png" medium="image" type="image/png"/>
      <pubDate>Fri, 28 Aug 2026 12:00:00 GMT</pubDate>
      <description>WatchGuard Dimension is susceptible to a denial-of-service condition when an attacker sends a high volume of TCP SYN packets to the log listening service. Fix documented: 2.3.1 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-19314 · CVSS 8.7 · Fireware OS</title>
      <link>https://cvebrief.com/cve/cve-2026-19314/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-watchguard-CVE-2026-19314</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/watchguard.png" medium="image" type="image/png"/>
      <pubDate>Fri, 28 Aug 2026 12:00:00 GMT</pubDate>
      <description>An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic. Fix documented: 2026.2.2 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-19316 · CVSS 8.7 · Fireware OS</title>
      <link>https://cvebrief.com/cve/cve-2026-19316/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-watchguard-CVE-2026-19316</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/watchguard.png" medium="image" type="image/png"/>
      <pubDate>Fri, 28 Aug 2026 12:00:00 GMT</pubDate>
      <description>A double-free vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic. Fix documented: 2026.2.2 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-19317 · CVSS 8.7 · Fireware OS</title>
      <link>https://cvebrief.com/cve/cve-2026-19317/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-watchguard-CVE-2026-19317</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/watchguard.png" medium="image" type="image/png"/>
      <pubDate>Fri, 28 Aug 2026 12:00:00 GMT</pubDate>
      <description>An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic. Fix documented: 2026.2.2 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-78008 · CVSS 8.6 · Fireware OS</title>
      <link>https://cvebrief.com/cve/cve-2026-78008/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-watchguard-CVE-2026-78008</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/watchguard.png" medium="image" type="image/png"/>
      <pubDate>Fri, 28 Aug 2026 12:00:00 GMT</pubDate>
      <description>A buffer overflow vulnerability in the WatchGuard Fireware OS Management Web UI allows an authenticated administrator with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic. Fix documented: 2026.2.2 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-78009 · CVSS 8.7 · Fireware OS</title>
      <link>https://cvebrief.com/cve/cve-2026-78009/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-watchguard-CVE-2026-78009</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/watchguard.png" medium="image" type="image/png"/>
      <pubDate>Fri, 28 Aug 2026 12:00:00 GMT</pubDate>
      <description>An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic. Fix documented: 2026.2.2 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-78010 · CVSS 8.7 · Fireware OS</title>
      <link>https://cvebrief.com/cve/cve-2026-78010/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-watchguard-CVE-2026-78010</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/watchguard.png" medium="image" type="image/png"/>
      <pubDate>Fri, 28 Aug 2026 12:00:00 GMT</pubDate>
      <description>A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process iallows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic. Fix documented: 2026.2.2 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-78011 · CVSS 8.7 · Fireware OS</title>
      <link>https://cvebrief.com/cve/cve-2026-78011/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-watchguard-CVE-2026-78011</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/watchguard.png" medium="image" type="image/png"/>
      <pubDate>Fri, 28 Aug 2026 12:00:00 GMT</pubDate>
      <description>An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic. Fix documented: 2026.2.2 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-78610 · CVSS 8.4 · Dimension</title>
      <link>https://cvebrief.com/cve/cve-2026-78610/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-watchguard-CVE-2026-78610</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/watchguard.png" medium="image" type="image/png"/>
      <pubDate>Fri, 28 Aug 2026 12:00:00 GMT</pubDate>
      <description>WatchGuard Dimension&apos;s Web UI exposes an administrator passphrase change action that lacks CSRF protection. Fix documented: 2.3.1 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-78612 · CVSS 8.6 · Dimension</title>
      <link>https://cvebrief.com/cve/cve-2026-78612/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-watchguard-CVE-2026-78612</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/watchguard.png" medium="image" type="image/png"/>
      <pubDate>Fri, 28 Aug 2026 12:00:00 GMT</pubDate>
      <description>WatchGuard Dimension contains an authenticated SQL injection vulnerability in the scheduled report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted r Fix documented: 2.3.1 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-78613 · CVSS 8.6 · Dimension</title>
      <link>https://cvebrief.com/cve/cve-2026-78613/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-watchguard-CVE-2026-78613</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/watchguard.png" medium="image" type="image/png"/>
      <pubDate>Fri, 28 Aug 2026 12:00:00 GMT</pubDate>
      <description>WatchGuard Dimension contains an authenticated SQL injection vulnerability in the log viewer feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted request Fix documented: 2.3.1 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-78614 · CVSS 8.6 · Dimension</title>
      <link>https://cvebrief.com/cve/cve-2026-78614/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-watchguard-CVE-2026-78614</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/watchguard.png" medium="image" type="image/png"/>
      <pubDate>Fri, 28 Aug 2026 12:00:00 GMT</pubDate>
      <description>WatchGuard Dimension contains an authenticated SQL injection vulnerability in the audit report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted reque Fix documented: 2.3.1 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-13050 · CVSS 8.6 · Fireware OS</title>
      <link>https://cvebrief.com/cve/cve-2026-13050/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-watchguard-CVE-2026-13050</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/watchguard.png" medium="image" type="image/png"/>
      <pubDate>Fri, 03 Jul 2026 12:00:00 GMT</pubDate>
      <description>An Out-of-bounds Write vulnerability in WatchGuard Fireware OS networkd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI Fix documented: 2026.2.1 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-13053 · CVSS 8.6 · Fireware OS</title>
      <link>https://cvebrief.com/cve/cve-2026-13053/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-watchguard-CVE-2026-13053</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/watchguard.png" medium="image" type="image/png"/>
      <pubDate>Fri, 03 Jul 2026 12:00:00 GMT</pubDate>
      <description>An Out-of-bounds Write vulnerability in WatchGuard Fireware OS&apos;s CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command Fix documented: 2026.2.1 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-13054 · CVSS 8.6 · Fireware OS</title>
      <link>https://cvebrief.com/cve/cve-2026-13054/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-watchguard-CVE-2026-13054</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/watchguard.png" medium="image" type="image/png"/>
      <pubDate>Fri, 03 Jul 2026 12:00:00 GMT</pubDate>
      <description>A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated attacker to write arbitrary files on the Firebox&apos;s filesystem Fix documented: 2026.2.1 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-13084 · CVSS 8.7 · Fireware OS</title>
      <link>https://cvebrief.com/cve/cve-2026-13084/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-watchguard-CVE-2026-13084</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/watchguard.png" medium="image" type="image/png"/>
      <pubDate>Fri, 03 Jul 2026 12:00:00 GMT</pubDate>
      <description>A null pointer dereference vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to create a denial-of-service (DoS) condition by sending specially crafted IKEv2 messages Fix documented: 2026.2.1 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-13368 · CVSS 9.2 · Fireware OS</title>
      <link>https://cvebrief.com/cve/cve-2026-13368/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-watchguard-CVE-2026-13368</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/watchguard.png" medium="image" type="image/png"/>
      <pubDate>Fri, 03 Jul 2026 12:00:00 GMT</pubDate>
      <description>A use-after-free race condition in WatchGuard Fireware OS allows unauthenticated remote attackers to execute arbitrary code via the IKEv2 Mobile VPN. Fix documented: 2026.2.1 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-13383 · CVSS 8.6 · Fireware OS</title>
      <link>https://cvebrief.com/cve/cve-2026-13383/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-watchguard-CVE-2026-13383</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/watchguard.png" medium="image" type="image/png"/>
      <pubDate>Fri, 03 Jul 2026 12:00:00 GMT</pubDate>
      <description>An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI Fix documented: 2026.2.1 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-13384 · CVSS 8.6 · Fireware OS</title>
      <link>https://cvebrief.com/cve/cve-2026-13384/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-watchguard-CVE-2026-13384</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/watchguard.png" medium="image" type="image/png"/>
      <pubDate>Fri, 03 Jul 2026 12:00:00 GMT</pubDate>
      <description>An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI Fix documented: 2026.2.1 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-13722 · CVSS 8.6 · Fireware OS</title>
      <link>https://cvebrief.com/cve/cve-2026-13722/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-watchguard-CVE-2026-13722</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/watchguard.png" medium="image" type="image/png"/>
      <pubDate>Fri, 03 Jul 2026 12:00:00 GMT</pubDate>
      <description>WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image via the backup/restore feature Fix documented: 2026.2.1 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-8247 · CVSS 7.7 · Fireware OS</title>
      <link>https://cvebrief.com/cve/cve-2026-8247/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-watchguard-CVE-2026-8247</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/watchguard.png" medium="image" type="image/png"/>
      <pubDate>Fri, 03 Jul 2026 12:00:00 GMT</pubDate>
      <description>An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker on the same local network segment to execute arbitrary code Fix documented: 2026.2.1 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-3342 · CVSS 7.2 · Fireware OS</title>
      <link>https://cvebrief.com/cve/cve-2026-3342/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-watchguard-CVE-2026-3342</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/watchguard.png" medium="image" type="image/png"/>
      <pubDate>Thu, 05 Mar 2026 12:00:00 GMT</pubDate>
      <description>An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an authenticated privileged administrator to execute arbitrary code with root permissions via an exposed management interface Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2025-14733 · CVSS 9.8 · actively exploited (CISA KEV) · Fireware OS</title>
      <link>https://cvebrief.com/cve/cve-2025-14733/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-watchguard-CVE-2025-14733</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/watchguard.png" medium="image" type="image/png"/>
      <pubDate>Sat, 20 Dec 2025 12:00:00 GMT</pubDate>
      <description>An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. Fix documented: 2025.1.4 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2025-9242 · CVSS 9.5 · actively exploited (CISA KEV) · Fireware OS</title>
      <link>https://cvebrief.com/cve/cve-2025-9242/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-watchguard-CVE-2025-9242</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/watchguard.png" medium="image" type="image/png"/>
      <pubDate>Thu, 13 Nov 2025 12:00:00 GMT</pubDate>
      <description>WatchGuard Firebox Out-of-Bounds Write Vulnerability - Active in CISA KEV catalog. Fix documented: 12.11.4 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
  </channel>
</rss>
