CVE-2026-13376: WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in spamBlocker Module
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS spamBlocker module allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-1071.
This issue affects Fireware OS 12.0 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13376?
The severity of CVE-2026-13376 is medium with a CVSS score of 4.8.
How do I fix CVE-2026-13376?
To fix CVE-2026-13376, it is recommended to update to the latest version of WatchGuard Fireware OS that addresses this vulnerability.
What kind of vulnerability is CVE-2026-13376?
CVE-2026-13376 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the spamBlocker module of WatchGuard Fireware OS.
What versions of Fireware OS are affected by CVE-2026-13376?
CVE-2026-13376 affects WatchGuard Fireware OS versions 12.0 and up to and including the version that addresses this issue.
Is CVE-2026-13376 linked to any other vulnerabilities?
Yes, CVE-2026-13376 serves as an additional unmitigated attack path for CVE-2025-1071.