CVE-2026-13374: WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in ConnectWise Technology Integration Configuration
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (ConnectWise Technology Integration module) allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-13937.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13374?
CVE-2026-13374 has a medium severity rating of 4.8 according to the CVSS scoring system.
What are the potential impacts of CVE-2026-13374?
The potential impact of CVE-2026-13374 includes the ability for attackers to execute malicious scripts in the context of the user's session.
How do I mitigate CVE-2026-13374?
Mitigation for CVE-2026-13374 involves applying the latest security patches provided by WatchGuard for the Fireware OS.
Which software versions are affected by CVE-2026-13374?
CVE-2026-13374 affects various versions of the WatchGuard Fireware OS, particularly in the ConnectWise Technology Integration module.
Is CVE-2026-13374 linked to any other vulnerabilities?
Yes, CVE-2026-13374 is an additional unmitigated attack path for the previously reported CVE-2025-13937.