CVE-2026-8247: WatchGuard Firebox admd Out of Bounds Write Vulnerability
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker on the same local network segment to execute arbitrary code.
This vulnerability affects Fireware OS 11.0 up to and including 11.12.4Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 2026.2.1 - Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 12.12.1 - Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 12.5.19 - Compensating control
Because the vulnerability is exploitable by an unauthenticated attacker on the same local network segment, restrict access to the Firebox/Fireware management and any exposed services from untrusted hosts on the local network (e.g., via network segmentation/ACL/firewall rules) until patched.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8247?
CVE-2026-8247 has a severity score of 7.7, classified as high risk.
What software is affected by CVE-2026-8247?
CVE-2026-8247 affects WatchGuard Fireware OS versions from 11.0 to 11.12.4_Update1, 12.0 to 12.12, and 2025.1.
How do I fix CVE-2026-8247?
To mitigate CVE-2026-8247, upgrade to a patched version of WatchGuard Fireware OS as specified by the vendor.
What type of attack can exploit CVE-2026-8247?
CVE-2026-8247 can be exploited by an unauthenticated attacker on the same local network segment to execute arbitrary code.
When was CVE-2026-8247 published?
CVE-2026-8247 was published on July 2, 2026.