CVE-2026-13384: WatchGuard Firebox wgagent Out of Bounds Write Vulnerability
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 2025.1 up to and including 2026.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13384?
CVE-2026-13384 has a high severity rating of 8.6 according to the CVSS scoring system.
How do I fix CVE-2026-13384?
To remediate CVE-2026-13384, update your WatchGuard Fireware OS to the latest version that addresses this out-of-bounds write vulnerability.
Who is affected by CVE-2026-13384?
CVE-2026-13384 affects authenticated privileged users of WatchGuard Fireware OS versions 12.1 to 12.12 and 2025.1.
What type of vulnerability is CVE-2026-13384?
CVE-2026-13384 is categorized as an Out-of-Bounds Write vulnerability.
Can CVE-2026-13384 be exploited remotely?
CVE-2026-13384 can potentially be exploited remotely if an authenticated privileged user sends specially crafted requests to the Management Web UI.