CVEs we hold for Watchguard
Records whose assigning authority named Watchguard as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-86135Dimension CSRF Vulnerability in Database Snapshot Creation Allows Denial of ServiceWatchGuard Dimension
CVE-2026-81851Fireware OS Heap-Based Buffer Overflow in iked Allows Denial of ServiceWatchGuard Fireware OS
CVE-2026-78618Dimension Business Logic Flaw Allows Chained Backend Object OperationsWatchGuard Dimension
CVE-2026-78617WatchGuard Dimension Web UI Authentication Brute-Force Due to Missing Rate LimitingWatchGuard Dimension
CVE-2026-78615WatchGuard Dimension Reflected DOM-Based XSS in Report Detail PageWatchGuard Dimension
CVE-2026-78610Dimension CSRF Vulnerability in Administrator Passphrase Change EndpointWatchGuard Dimension
CVE-2026-78498Dimension Server-Side Request Forgery via Email Server Test SettingsWatchGuard Dimension
CVE-2026-78495Dimension Server-Side Request Forgery via Remote Backup Connection TestWatchGuard Dimension
CVE-2026-78174WatchGuard Dimension Session Hijack via Exposed Session Tokens in Diagnostic LogsWatchGuard Dimension
CVE-2026-78011Fireware OS Integer Underflow in Iked Allows Unauthenticated Denial of Service (DoS)WatchGuard Fireware OS
CVE-2026-78010Fireware OS Stack-Based Buffer Overflow in iked Allows Unauthenticated Denial of ServiceWatchGuard Fireware OS
CVE-2026-78009Fireware OS Out-of-Bounds Read in iked Allows Unauthenticated Denial of Service (DoS)WatchGuard Fireware OS
CVE-2026-6788Uncontrolled search path in PluginLauncher allows SYSTEM code execution in WatchGuard AgentWatchGuard Agent
CVE-2026-6787Usage of a hard-coded cryptographic key in WatchGuard Agent allows inclusion of code into existing processWatchGuard Agent
CVE-2026-57910WatchGuard Agent improper authentication allows unauthenticated remote code executionWatchGuard Agent
CVE-2026-57909WatchGuard Agent path traversal allows unauthenticated remote code executionWatchGuard Agent
CVE-2026-4315WatchGuard Firebox Cross-Site Request Forgery (CSRF) in Fireware Web UIWatchGuard Fireware OS
CVE-2026-4266WatchGuard Firebox Insecure Deserialization in Fireware Access PortalWatchGuard Fireware OS
CVE-2026-41287Stack-based Buffer Overflow in WatchGuard Agent Discovery Service on Windows Causes Denial of Service - Variant AWatchGuard Agent
CVE-2026-41286Stack-based Buffer Overflow in WatchGuard Agent Discovery Service on Windows Causes Denial of Service - Variant BWatchGuard Agent
CVE-2026-3987WatchGuard Firebox Arbitrary File Write vis Path Traversal in Fireware Web UIWatchGuard Fireware OS
CVE-2026-3343WatchGuard Firebox Reflected Cross-Site-Scripting (XSS) Vulnerability in Fireware Web UIWatchGuard Fireware OS
CVE-2026-19318Fireware OS Pre-Authentication Stack Buffer Overflow in iked Allows Remote Code ExecutionWatchGuard Fireware OS
CVE-2026-19317Fireware OS Pre-Authentication Out-of-Bounds Read in iked Allows Denial of Service (DoS)WatchGuard Fireware OS
CVE-2026-19316Fireware OS Pre-Authentication Double Free in iked Allows Denial of Service (DoS)WatchGuard Fireware OS
CVE-2026-19315Fireware OS Pre-Authentication Type Confusion in iked Allows Remote Code ExecutionWatchGuard Fireware OS
CVE-2026-19314Fireware OS Integer Underflow in iked Allows Unauthenticated Denial of Service (DoS)WatchGuard Fireware OS
CVE-2026-19313Fireware OS Pre-Authentication Heap Buffer Overflow in iked Allows Remote Code ExecutionWatchGuard Fireware OS
CVE-2026-13728WatchGuard Firebox Hardcoded Fallback Encryption Key in Access Portal Resource Credential DatabaseWatchGuard Fireware OS
CVE-2026-13722WatchGuard Firebox Firmware Image Validation Bypass in WatchGuard Fireware OSWatchGuard Fireware OS
CVE-2026-13377WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in SIP Proxy ConfigurationWatchGuard Fireware OS
CVE-2026-13376WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in spamBlocker ModuleWatchGuard Fireware OS
CVE-2026-13375WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Autotask Technology Integration ConfigurationWatchGuard Fireware OS
CVE-2026-13374WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in ConnectWise Technology Integration ConfigurationWatchGuard Fireware OS
CVE-2026-13373WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Tigerpaw Technology Integration ConfigurationWatchGuard Fireware OS
CVE-2026-13371WatchGuard Firebox Management Web UI Denial of Service via Unsafe DeserializationWatchGuard Fireware OS
CVE-2026-13368WatchGuard Firebox Race Condition and Use-After-Free in Mobile VPN with IKEv2 LDAP AuthenticationWatchGuard Fireware OS
CVE-2026-13086Fireware OS Stack-Based Buffer Overflow in Mobile Security epm EndpointWatchGuard Fireware OS
CVE-2026-13079WatchGuard Mobile VPN with SSL Windows Client Local Privilege EscalationWatchGuard Mobile VPN with SSL Client
CVE-2026-13054WatchGuard Firebox Arbitrary File Write via Path Traversal in Management Web UIWatchGuard Fireware OS
CVE-2026-13053WatchGuard Firebox Authenticated Out of Bounds Write in Management CLI Command HandlerWatchGuard Fireware OS
CVE-2025-6999WatchGuard Firebox Authentication Portal Request Smuggling VulnerabilityWatchGuard Fireware OS
CVE-2025-6947WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in SIP Proxy ConfigurationWatchGuard Fireware OS
CVE-2025-6946WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in IPS ConfigurationWatchGuard Fireware OS
CVE-2025-4805WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Acces Portal ConfigurationWatchGuard Fireware OS
CVE-2025-4804WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Hotpot ConfigurationWatchGuard Fireware OS
CVE-2025-2782WatchGuard Terminal Services Agent Local Privilege Escalation via Non-Standard Installation DirectoryWatchGuard SSO Terminal Services Agent
CVE-2025-2781WatchGuard Mobile VPN with SSL Local Privilege Escalation via Non-Standard Installation DirectoryWatchGuard Mobile VPN with SSL Client
CVE-2025-1910WatchGuard Mobile VPN with SSL Local Privilege Escalation via Update PackageWatchGuard Mobile VPN with SSL Client
CVE-2025-1549WatchGuard Mobile VPN with SSL Local Privilege EscallationWatchGuard Mobile VPN with SSL Client
CVE-2025-1547WatchGuard Firebox Authenticated Stack Overflow in Certificate Request CommandWatchGuard Fireware OS
CVE-2025-13939WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Gateway Wireless ControllerWatchGuard Fireware OS
CVE-2025-13938WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Autotask Technology Integration ConfigurationWatchGuard Fireware OS
CVE-2025-13937WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in ConnectWise Technology Integration ConfigurationWatchGuard Fireware OS
CVE-2025-13936WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Tigerpaw Technology Integration ConfigurationWatchGuard Fireware OS
CVE-2025-1239WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Blocked Sites ListWatchGuard Fireware OS
CVE-2025-12196WatchGuard Firebox Authenticated Out of Bounds Write in Management CLI Ping CommandWatchGuard Fireware OS
CVE-2025-12195WatchGuard Firebox Authenticated Out of Bounds Write in Management CLI IPSec ConfigurationWatchGuard Fireware OS
CVE-2025-1071WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in spamBlocker ModuleWatchGuard Fireware OS
CVE-2024-8424WatchGuard Endpoint Protection Privilege Escalation in PSANHost Enables Arbitrary File Delete as SYSTEMWatchGuard Panda Dome
CVE-2024-6593WatchGuard Firebox Single Sign-On Agent Management Interface Authentication BypassWatchGuard SSO Agent
CVE-2024-6592WatchGuard Firebox Single Sign-On Agent Protocol Authorization BypassWatchGuard SSO Agent
CVE-2024-4944Mobile VPN with SSL Local Privilege Escalation VulnerabilityWatchGuard Mobile VPN with SSL Client
CVE-2024-1417Local Code Injection Vulnerability in AuthPoint Password Manager App for macOS SafariWatchGuard AuthPoint Password Manager
CVE-2022-31749Authenticated arbitrary file read/write in WatchGuard Fireware OSWatchGuard Fireware OS
94 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.