Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.6

WatchGuard Fireware OS allows unapproved system changes via administration interface

CVE-2026-3342
Summary

WatchGuard Fireware OS, used in some firewalls, has a security flaw that allows a privileged administrator to make unauthorized changes to the system. This could lead to the system being compromised. Affected versions should be updated to the latest patches.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
watchguard fireware > 12.5 , <= 12.5.17
watchguard fireware > 2025.1 , <= 2026.1.2
watchguard fireware > 11.9 , <= 12.11.8
Original title
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an authenticated privileged administrator to execute arbitrary code with root permissions via an exposed management interfac...
Original description
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an authenticated privileged administrator to execute arbitrary code with root permissions via an exposed management interface.

This vulnerability affects Fireware OS 11.9 up to and including 11.12.4_Update1, 12.0 up to and including 12.11.7 and 2025.1 up to and including 2026.1.1.
nvd CVSS3.1 7.2
nvd CVSS4.0 8.6
Vulnerability type
CWE-787 Out-of-bounds Write
Published: 3 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026