CVE-2026-13728: WatchGuard Firebox Hardcoded Fallback Encryption Key in Access Portal Resource Credential Database
In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved credentials for Access Portal resources.
This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 2025.1 up to and including 2026.2. This vulnerability does not affect devices that do not support the Access Portal feature or standalone Fireboxes not deployed in a FireCluster.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13728?
CVE-2026-13728 has a medium severity rating of 5.9 according to CVSS.
How do I fix CVE-2026-13728?
To mitigate CVE-2026-13728, upgrade WatchGuard Fireware OS to a version beyond 12.12 or 2026.2.
What software is affected by CVE-2026-13728?
CVE-2026-13728 affects WatchGuard Fireware OS versions 12.1 through 12.12 and 2025.1 through 2026.2.
What does CVE-2026-13728 involve?
CVE-2026-13728 involves the use of a hard-coded fallback encryption key for encrypting saved credentials in Access Portal resources.
Is user interaction required for CVE-2026-13728 to be exploited?
No, user interaction is not required for the exploitation of CVE-2026-13728.