CVE-2026-13375: WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Autotask Technology Integration Configuration
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Autotask Technology Integration module) allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-13938.
This issue affects Fireware OS 12.4 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WatchGuard Fireware OS (Autotask Technology Integration module)to a version that resolves this vulnerability.Fixed in 12.12 - Upgrade
Upgrade
WatchGuard Fireware OS (Autotask Technology Integration module)to a version that resolves this vulnerability.Fixed in 12.5.18 - Upgrade
Upgrade
WatchGuard Fireware OS (Autotask Technology Integration module)to a version that resolves this vulnerability.Fixed in 2026.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13375?
The severity of CVE-2026-13375 is rated as 40.
How do I fix CVE-2026-13375?
To mitigate CVE-2026-13375, ensure that your WatchGuard Fireware OS is updated to the latest version that addresses this vulnerability.
What systems are affected by CVE-2026-13375?
CVE-2026-13375 affects the Autotask Technology Integration module within WatchGuard Fireware OS.
What type of vulnerability is CVE-2026-13375?
CVE-2026-13375 is classified as a Stored Cross-Site Scripting (XSS) vulnerability.
Is CVE-2026-13375 related to any other vulnerabilities?
CVE-2026-13375 is an additional attack path related to CVE-2025-13938, enhancing the risk for affected systems.