CVE-2026-13371: WatchGuard Firebox Management Web UI Denial of Service via Unsafe Deserialization
An authenticated administrator can trigger a denial-of-service condition in the Fireware Management Web UI by sending malformed or crafted data to the putdata endpoint, which performs unsafe deserialization of the attacker-supplied input.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13371?
The severity of CVE-2026-13371 is classified as medium with a CVSS score of 6.9.
How do I fix CVE-2026-13371?
To fix CVE-2026-13371, ensure you are running the latest version of the WatchGuard Firebox Management Web UI that addresses this vulnerability.
What type of attack is CVE-2026-13371 associated with?
CVE-2026-13371 is associated with a denial-of-service attack via unsafe deserialization.
Who can exploit CVE-2026-13371?
An authenticated administrator can exploit CVE-2026-13371 by sending malformed data to the put_data endpoint.
What impact does CVE-2026-13371 have on WatchGuard Firebox Management Web UI?
CVE-2026-13371 can result in a denial-of-service condition affecting the Fireware Management Web UI.