CVE-2026-13376: WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in spamBlocker Module
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS spamBlocker module allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-1071.
This issue affects Fireware OS 12.0 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WatchGuard Fireware OS spamBlocker moduleto a version that resolves this vulnerability.Fixed in 12.12 - Compensating control
Mitigate the additional stored XSS attack path in the spamBlocker module by applying network/edge controls (e.g., restrict/segment access to any web interfaces or endpoints that render spamBlocker-generated content) until the affected Fireware OS is upgraded.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13376?
The severity of CVE-2026-13376 is medium with a CVSS score of 4.8.
How do I fix CVE-2026-13376?
To fix CVE-2026-13376, it is recommended to update to the latest version of WatchGuard Fireware OS that addresses this vulnerability.
What kind of vulnerability is CVE-2026-13376?
CVE-2026-13376 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the spamBlocker module of WatchGuard Fireware OS.
What versions of Fireware OS are affected by CVE-2026-13376?
CVE-2026-13376 affects WatchGuard Fireware OS versions 12.0 and up to and including the version that addresses this issue.
Is CVE-2026-13376 linked to any other vulnerabilities?
Yes, CVE-2026-13376 serves as an additional unmitigated attack path for CVE-2025-1071.