CVE-2026-13384: WatchGuard Firebox wgagent Out of Bounds Write Vulnerability
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WatchGuard Firebox Fireware OS (wgagent)to a version that resolves this vulnerability.Fixed in 2026.2.1 - Upgrade
Upgrade
WatchGuard Firebox Fireware OS (wgagent)to a version that resolves this vulnerability.Fixed in 12.12.1 - Upgrade
Upgrade
WatchGuard Firebox Fireware OS (wgagent)to a version that resolves this vulnerability.Fixed in 12.5.19 - Compensating control
Apply mitigations by restricting access to the Management Web UI to authenticated privileged users only, and limit Management Web UI exposure (e.g., via network ACL/firewall) to reduce the ability to send specially crafted requests.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13384?
CVE-2026-13384 has a high severity rating of 8.6 according to the CVSS scoring system.
How do I fix CVE-2026-13384?
To remediate CVE-2026-13384, update your WatchGuard Fireware OS to the latest version that addresses this out-of-bounds write vulnerability.
Who is affected by CVE-2026-13384?
CVE-2026-13384 affects authenticated privileged users of WatchGuard Fireware OS versions 12.1 to 12.12 and 2025.1.
What type of vulnerability is CVE-2026-13384?
CVE-2026-13384 is categorized as an Out-of-Bounds Write vulnerability.
Can CVE-2026-13384 be exploited remotely?
CVE-2026-13384 can potentially be exploited remotely if an authenticated privileged user sends specially crafted requests to the Management Web UI.