CVE-2026-13373: WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Tigerpaw Technology Integration Configuration
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Tigerpaw Technology Integration module) allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-13936.
This issue affects Fireware OS 12.4 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13373?
CVE-2026-13373 has a medium severity rating of 4.8 according to the CVSS.
How do I fix CVE-2026-13373?
To remediate CVE-2026-13373, apply the latest patches provided by WatchGuard for the Fireware OS.
What kind of vulnerability is CVE-2026-13373?
CVE-2026-13373 is a stored cross-site scripting (XSS) vulnerability affecting the Tigerpaw Technology Integration configuration in WatchGuard Fireware OS.
What systems are affected by CVE-2026-13373?
CVE-2026-13373 affects the WatchGuard Fireware OS when using the Tigerpaw Technology Integration module.
When was CVE-2026-13373 published?
CVE-2026-13373 was published on July 2, 2026.