Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

11 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Critical9.3WatchGuard Updated

Critical [CVE-2026-78174] WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log

WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-privileged Dimension Administrator can retrieve this log and extract a Super Administrator's session token while that administrator is logged in, enabling account takeover.

CVE-2026-78174
System Manager
Aug 27, 2026
Critical9.3WatchGuard Updated

Critical [CVE-2026-19315] type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic

A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

CVE-2026-19315
Firebox / Fireware
Aug 27, 2026
Critical9.3WatchGuard Updated

Critical [CVE-2026-13086] stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecated Mobile Security feature in WatchGuard Fireware OS allows an unauthenticated remote attacker to execute arbitrary code

A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecated Mobile Security feature in WatchGuard Fireware OS allows an unauthenticated remote attacker to execute arbitrary code.

CVE-2026-13086
Firebox / Fireware
Aug 27, 2026
Critical9.3WatchGuard Updated

Critical [CVE-2026-19313] heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic

An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

CVE-2026-19313
Firebox / Fireware
Aug 27, 2026
Critical9.3WatchGuard Updated

Critical [CVE-2026-19318] stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic

A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

CVE-2026-19318
Firebox / Fireware
Aug 27, 2026
Critical9.3WatchGuard Updated

Critical [CVE-2026-57910] Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary code with elevated privileges

Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary code with elevated privileges.

CVE-2026-57910
WatchGuard Agent / EPDR
Aug 25, 2026
Critical9.4WatchGuard Updated

Critical [CVE-2026-57909] path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to execute arbitrary code on an affected system

A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to execute arbitrary code on an affected system.

CVE-2026-57909
WatchGuard Agent / EPDR
Aug 25, 2026
Critical9.2WatchGuard Updated

Critical [CVE-2026-13368] WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2

WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2. A remote unauthenticated attacker could exploit this vulnerability to execute arbitrary code in the context of the iked process on Fireboxes that have a Mobile VPN with IKEv2 configured to use an external LDAP authentication server.

CVE-2026-13368
Firebox / Fireware
Jul 3, 2026
Critical9.3WatchGuard Exploited CISA KEV

Critical [CVE-2025-14733] WatchGuard Firebox iked Out of Bounds Write Vulnerability

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer.

CVE-2025-14733
Firebox / Fireware
Dec 19, 2025
Critical9.3WatchGuard

Critical [CVE-2024-6593] WatchGuard Firebox Single Sign-On Agent Management Interface Authentication Bypass

Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands. An attacker that has already gained network access could exploit this vulnerability to retrieve authenticated usernames and group memberships from the Single Sign-On Agent or tamper with the agent configuration. This vulnerability cannot be used by an attacker to gain access to user credentials. Affected product named by the advisory: SSO Agent.

CVE-2024-6593
Unclassified
Sep 25, 2024
Critical9.3WatchGuard

Critical [CVE-2024-6592] WatchGuard Firebox Single Sign-On Agent Protocol Authorization Bypass

An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker with network access to forge communications to affected components. In the event an attacker has already gained network access, they could exploit this vulnerability to retrieve authenticated usernames and group memberships from the Single Sign-On Agent or send arbitrary account and group information to the Single Sign-On Agent for their host. This vulnerability cannot be used by an attacker to gain access to user credentials. Affected products named by the advisory: SSO Client; SSO Agent.

CVE-2024-6592
Unclassified
Sep 25, 2024