CVE-2026-3343: WatchGuard Firebox Reflected Cross-Site-Scripting (XSS) Vulnerability in Fireware Web UI
A reflected cross-site scripting (XSS) vulnerability in the Fireware OS Web UI enabled execution of malicious JavaScript in the context of an authenticated management user's browser when they click on a specially crafted link.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WatchGuard Firebox Fireware OSto a version that resolves this vulnerability.Fixed in 2026.1.2 - Upgrade
Upgrade
WatchGuard Firebox Fireware OSto a version that resolves this vulnerability.Fixed in 12.11.8
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3343?
CVE-2026-3343 has been rated as medium severity due to its potential to execute malicious JavaScript in an authenticated user's browser.
How do I fix CVE-2026-3343?
To fix CVE-2026-3343, users should upgrade to Fireware OS versions 12.11.8 or later, or 2026.1.2 or later.
Who is affected by CVE-2026-3343?
CVE-2026-3343 affects authenticated users of the Fireware Web UI across several Firebox models running vulnerable versions of Fireware OS.
What type of vulnerability is CVE-2026-3343?
CVE-2026-3343 is categorized as a reflected cross-site scripting (XSS) vulnerability.
What can attackers achieve with CVE-2026-3343?
Attackers can execute arbitrary JavaScript in the context of an authenticated management user's browser, potentially leading to data theft or manipulation.