CVE-2026-13722: WatchGuard Firebox Firmware Image Validation Bypass in WatchGuard Fireware OS
WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image via the backup/restore feature. An authenticated administrator can exploit this vulnerability to install a tampered firmware image.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WatchGuard Firebox Firmware (WatchGuard Fireware OS)to a version that resolves this vulnerability.Fixed in 2026.2.1 - Upgrade
Upgrade
WatchGuard Firebox Firmware (WatchGuard Fireware OS)to a version that resolves this vulnerability.Fixed in 12.12.1 - Upgrade
Upgrade
WatchGuard Firebox Firmware (WatchGuard Fireware OS)to a version that resolves this vulnerability.Fixed in 12.11.9
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13722?
CVE-2026-13722 is rated as high severity with a score of 8.6 according to CVSS.
How do I fix CVE-2026-13722?
To mitigate CVE-2026-13722, ensure that you upgrade to a patched version of WatchGuard Fireware OS that resolves the firmware validation bypass.
What impact does CVE-2026-13722 have on my system?
CVE-2026-13722 allows an authenticated administrator to install a tampered firmware image which can lead to full system compromise.
Which versions of WatchGuard Fireware OS are affected by CVE-2026-13722?
CVE-2026-13722 affects Fireware OS versions from 11.0 up to and including 11.12.4_Update.
Who can exploit CVE-2026-13722?
Only authenticated administrators have the ability to exploit CVE-2026-13722 due to the nature of the vulnerability.