Skip to content
VulniPulse

WatchGuard Security Advisories & CVEs

60 advisories tracked · WatchGuard PSIRT Advisories via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor WatchGuard CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your WatchGuard device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in WatchGuard's recent advisories.

Official source

WatchGuard PSIRT Advisories via NVD

WatchGuard is not its own NVD CNA and its PSIRT portal has no machine-readable feed, so VulniPulse ingests WatchGuard's CVEs from NVD (keyword-filtered to WatchGuard, requiring a WatchGuard product in the description) and links each CVE back to the wgrd-psirt advisory when referenced. Covers Fireware OS on the Firebox firewall line, WatchGuard System Manager, the WatchGuard Agent / EPDR endpoint and AuthPoint MFA — SMB firewalls previously mass-exploited by the Cyclops Blink botnet, so a patch-now audience.

Latest WatchGuard advisories

Medium4.8WatchGuard

Medium [CVE-2025-13938] WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Autotask Technology Integration Configuration

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Autotask Technology Integration module) allows Stored XSS.

CVE-2025-13938
Firebox / Fireware
Dec 4, 2025
Medium4.8WatchGuard

Medium [CVE-2025-13937] WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in ConnectWise Technology Integration Configuration

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (ConnectWise Technology Integration module) allows Stored XSS.

CVE-2025-13937
Firebox / Fireware
Dec 4, 2025
Medium4.8WatchGuard

Medium [CVE-2025-13936] WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Tigerpaw Technology Integration Configuration

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Tigerpaw Technology Integration module) allows Stored XSS.

CVE-2025-13936
Firebox / Fireware
Dec 4, 2025
Medium6.3WatchGuard

Medium [CVE-2024-4944 +1] WatchGuard Mobile VPN with SSL Local Privilege Escallation

A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands with elevated privileges on the Windows system. This vulnerability is an additional unmitigated attack path for CVE-2024-4944. This vulnerability is resolved in the Mobile VPN with SSL client for Windows version 12.11.5

CVE-2024-4944CVE-2025-1549
Unclassified
Oct 29, 2025
High8.9WatchGuard

High [CVE-2025-4106] WatchGuard Firebox leftover debug code vulnerability

An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by uploading a platform and version-specific diagnostic package and executing a leftover diagnostic command. Affected product named by the advisory: Fireware OS.

CVE-2025-4106
Firebox / Fireware
Oct 24, 2025
Medium4.8WatchGuard

Medium [CVE-2025-6947] WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in SIP Proxy Configuration

A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the SIP Proxy configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface of another management user. Affected product named by the advisory: Fireware OS.

CVE-2025-6947
Firebox / Fireware
Sep 15, 2025
Medium6.9WatchGuard

Medium [CVE-2025-6999] WatchGuard Firebox Authentication Portal Request Smuggling Vulnerability

An HTTP Request Smuggling [CWE-444] vulnerability in the Authentication portal of WatchGuard Fireware OS allows a remote attacker to evade request parameter sanitation and perform a reflected self-Cross-Site Scripting (XSS) attack. WatchGuard does not believe there is a practical exploit chain with a meaningful security impact for this vulnerability.

CVE-2025-6999
Firebox / Fireware
Sep 15, 2025
Medium4.8WatchGuard

Medium [CVE-2025-4805] WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Acces Portal Configuration

A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the Access Portal configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface of another management user. Affected product named by the advisory: Fireware OS.

CVE-2025-4805
Firebox / Fireware
May 16, 2025
Medium4.8WatchGuard

Medium [CVE-2025-4804] WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Hotpot Configuration

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS via the spamBlocker module. This vulnerability requires an authenticated administrator session to a locally managed Firebox.

CVE-2025-4804
Firebox / Fireware
May 16, 2025
Medium6.3WatchGuard

Medium [CVE-2025-2782] WatchGuard Terminal Services Agent Local Privilege Escalation via Non-Standard Installation Directory

The WatchGuard Terminal Services Agent on Windows does not properly configure directory permissions when installed in a non-default directory. This could allow an authenticated local attacker to escalate to SYSTEM privileges on a vulnerable system. Affected product named by the advisory: SSO Terminal Services Agent.

CVE-2025-2782
Unclassified
Mar 28, 2025
Medium6.3WatchGuard

Medium [CVE-2025-2781] WatchGuard Mobile VPN with SSL Local Privilege Escalation via Non-Standard Installation Directory

The WatchGuard Mobile VPN with SSL Client on Windows does not properly configure directory permissions when installed in a non-default directory. This could allow an authenticated local attacker to escalate to SYSTEM privileges on a vulnerable system.

CVE-2025-2781
Unclassified
Mar 28, 2025
Medium5.1WatchGuard

Medium [CVE-2025-0178] WatchGaurd Firebox Host Header Injection Vulnerability

An Improper Input Validation vulnerability in WatchGuard Fireware OS allows an attacker with network access to manipulate the value of the HTTP Host header in requests sent to the Web UI. An attacker could exploit this vulnerability to redirect users to malicious websites, poison the web cache, or inject malicious JavaScript into responses sent by the Web UI.

CVE-2025-0178
Firebox / Fireware
Feb 14, 2025
Medium4.8WatchGuard

Medium [CVE-2025-1239] WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Blocked Sites List

A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the Blocked Sites list. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface of another management user. Affected product named by the advisory: Fireware OS.

CVE-2025-1239
Firebox / Fireware
Feb 14, 2025
Medium4.8WatchGuard

Medium [CVE-2025-1071] WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in spamBlocker Module

A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the spamBlocker module. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface of another management user. Affected product named by the advisory: Fireware OS.

CVE-2025-1071
Firebox / Fireware
Feb 14, 2025
High8.5WatchGuard

High [CVE-2024-8424] WatchGuard Endpoint Protection Privilege Escalation in PSANHost Enables Arbitrary File Delete as SYSTEM

Improper Privilege Management vulnerability in WatchGuard EPDR, Panda AD360 and Panda Dome on Windows (PSANHost.exe module) allows arbitrary file delete with SYSTEM permissions. Affected products named by the advisory: Endpoint Security.

CVE-2024-8424
WatchGuard Agent / EPDR
Nov 7, 2024
Critical9.3WatchGuard

Critical [CVE-2024-6593] WatchGuard Firebox Single Sign-On Agent Management Interface Authentication Bypass

Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands. An attacker that has already gained network access could exploit this vulnerability to retrieve authenticated usernames and group memberships from the Single Sign-On Agent or tamper with the agent configuration. This vulnerability cannot be used by an attacker to gain access to user credentials. Affected product named by the advisory: SSO Agent.

CVE-2024-6593
Unclassified
Sep 25, 2024
Critical9.3WatchGuard

Critical [CVE-2024-6592] WatchGuard Firebox Single Sign-On Agent Protocol Authorization Bypass

An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker with network access to forge communications to affected components. In the event an attacker has already gained network access, they could exploit this vulnerability to retrieve authenticated usernames and group memberships from the Single Sign-On Agent or send arbitrary account and group information to the Single Sign-On Agent for their host. This vulnerability cannot be used by an attacker to gain access to user credentials. Affected products named by the advisory: SSO Client; SSO Agent.

CVE-2024-6592
Unclassified
Sep 25, 2024
High8.7WatchGuard

High [CVE-2024-6594] WatchGuard Firebox Single Sign-On Client Denial-of-Service

Improper Handling of Exceptional Conditions vulnerability in the WatchGuard Single Sign-On Client on Windows causes the client to crash while handling malformed commands. An attacker with network access to the client could create a denial of service condition for the Single Sign-On service by repeatedly issuing malformed commands. Affected product named by the advisory: SSO Client.

CVE-2024-6594
Unclassified
Sep 25, 2024
High8.6WatchGuard

High [CVE-2024-5974] Firebox Authenticated Buffer Overflow Vulnerability

A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with privileged management access to execute arbitrary code with system privileges on the firewall. This issue affects Fireware OS: from 11.9.6 through 12.10.3.

CVE-2024-5974
Firebox / Fireware
Jul 9, 2024
High8.6WatchGuard

High [CVE-2024-4944] Mobile VPN with SSL Local Privilege Escalation Vulnerability

A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands with elevated privileged.

CVE-2024-4944
Unclassified
Jul 9, 2024

← All vendors