CVE-2026-3343: WatchGuard Firebox Reflected Cross-Site-Scripting (XSS) Vulnerability in Fireware Web UI
A reflected cross-site scripting (XSS) vulnerability in the Fireware OS Web UI enabled execution of malicious JavaScript in the context of an authenticated management user's browser when they click on a specially crafted link.
This vulnerability affects Fireware OS 12.7 up to and including 12.11.7 and 2025.1 up to and including 2026.1.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3343?
CVE-2026-3343 has been rated as medium severity due to its potential to execute malicious JavaScript in an authenticated user's browser.
How do I fix CVE-2026-3343?
To fix CVE-2026-3343, users should upgrade to Fireware OS versions 12.11.8 or later, or 2026.1.2 or later.
Who is affected by CVE-2026-3343?
CVE-2026-3343 affects authenticated users of the Fireware Web UI across several Firebox models running vulnerable versions of Fireware OS.
What type of vulnerability is CVE-2026-3343?
CVE-2026-3343 is categorized as a reflected cross-site scripting (XSS) vulnerability.
What can attackers achieve with CVE-2026-3343?
Attackers can execute arbitrary JavaScript in the context of an authenticated management user's browser, potentially leading to data theft or manipulation.