CVE-2026-3987: WatchGuard Firebox Arbitrary File Write vis Path Traversal in Fireware Web UI
A path traversal vulnerability in the Fireware OS Web UI on WatchGuard Firebox systems may allow a privileged authenticated remote attacker to execute arbitrary code in the context of an elevated system process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3987?
CVE-2026-3987 is classified as a high severity vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2026-3987?
To remediate CVE-2026-3987, upgrade WatchGuard Fireware OS to versions 12.11.9 or higher, or 2026.1.3 or higher.
Who is affected by CVE-2026-3987?
CVE-2026-3987 affects WatchGuard Firebox systems running specific versions of Fireware OS between 12.6.1 and 12.11.8 as well as versions 2025.1 up to 2026.1.2.
What type of attack does CVE-2026-3987 enable?
CVE-2026-3987 allows a privileged authenticated remote attacker to perform an arbitrary file write, potentially leading to remote code execution.
What are the potential consequences of CVE-2026-3987?
The consequences of CVE-2026-3987 can include unauthorized system access, data manipulation, and the execution of malicious code within the affected system.