CVE-2026-13374: WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in ConnectWise Technology Integration Configuration
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (ConnectWise Technology Integration module) allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-13937.
This issue affects Fireware OS 12.4 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13374?
CVE-2026-13374 has a medium severity rating of 4.8 according to the CVSS scoring system.
What are the potential impacts of CVE-2026-13374?
The potential impact of CVE-2026-13374 includes the ability for attackers to execute malicious scripts in the context of the user's session.
How do I mitigate CVE-2026-13374?
Mitigation for CVE-2026-13374 involves applying the latest security patches provided by WatchGuard for the Fireware OS.
Which software versions are affected by CVE-2026-13374?
CVE-2026-13374 affects various versions of the WatchGuard Fireware OS, particularly in the ConnectWise Technology Integration module.
Is CVE-2026-13374 linked to any other vulnerabilities?
Yes, CVE-2026-13374 is an additional unmitigated attack path for the previously reported CVE-2025-13937.