Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-13086: WatchGuard Fireware OS lets remote attacker run code

CVE-2026-13086 · published 1 month ago
Summary

The Mobile Security component in WatchGuard Fireware OS has a flaw that lets anyone on the network send specially crafted data to the Endpoint Protection Manager service and take control of the device. This can happen without any login or user interaction. Install the latest firmware update from WatchGuard and, if you are not using the Mobile Security feature, disable it to remove the risk.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
watchguard fireware os < 2026.2.2
< 12.5.20
Original advisory text
Fireware OS Stack-Based Buffer Overflow in Mobile Security epm Endpoint
A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecated Mobile Security feature in WatchGuard Fireware OS allows an unauthenticated remote attacker to execute arbitrary code.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.3 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-121Stack-based Buffer Overflow
CWE-787Out-of-bounds Write
CWE-798Use of Hard-coded Credentials
Timeline
Published28 Aug 2026
Updated27 Sep 2026
First seen29 Aug 2026
Sources
CVE-2026-13086 · MITRE
Track software like this
Free during beta