Skip to content
VulniPulse

WatchGuard Security Advisories & CVEs

87 advisories tracked · WatchGuard PSIRT Advisories via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor WatchGuard CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your WatchGuard device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in WatchGuard's recent advisories.

Official source

WatchGuard PSIRT Advisories via NVD

WatchGuard is not its own NVD CNA and its PSIRT portal has no machine-readable feed, so VulniPulse ingests WatchGuard's CVEs from NVD (keyword-filtered to WatchGuard, requiring a WatchGuard product in the description) and links each CVE back to the wgrd-psirt advisory when referenced. Covers Fireware OS on the Firebox firewall line, WatchGuard System Manager, the WatchGuard Agent / EPDR endpoint and AuthPoint MFA — SMB firewalls previously mass-exploited by the Cyclops Blink botnet, so a patch-now audience.

Latest WatchGuard advisories

Medium4.8WatchGuard

Medium [CVE-2025-1071] WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in spamBlocker Module

A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the spamBlocker module. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface of another management user. Affected product named by the advisory: Fireware OS.

CVE-2025-1071
Firebox / Fireware
Feb 14, 2025
High8.5WatchGuard

High [CVE-2024-8424] WatchGuard Endpoint Protection Privilege Escalation in PSANHost Enables Arbitrary File Delete as SYSTEM

Improper Privilege Management vulnerability in WatchGuard EPDR, Panda AD360 and Panda Dome on Windows (PSANHost.exe module) allows arbitrary file delete with SYSTEM permissions. Affected products named by the advisory: Endpoint Security.

CVE-2024-8424
WatchGuard Agent / EPDR
Nov 7, 2024
Critical9.3WatchGuard

Critical [CVE-2024-6593] WatchGuard Firebox Single Sign-On Agent Management Interface Authentication Bypass

Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands. An attacker that has already gained network access could exploit this vulnerability to retrieve authenticated usernames and group memberships from the Single Sign-On Agent or tamper with the agent configuration. This vulnerability cannot be used by an attacker to gain access to user credentials. Affected product named by the advisory: SSO Agent.

CVE-2024-6593
Unclassified
Sep 25, 2024
Critical9.3WatchGuard

Critical [CVE-2024-6592] WatchGuard Firebox Single Sign-On Agent Protocol Authorization Bypass

An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker with network access to forge communications to affected components. In the event an attacker has already gained network access, they could exploit this vulnerability to retrieve authenticated usernames and group memberships from the Single Sign-On Agent or send arbitrary account and group information to the Single Sign-On Agent for their host. This vulnerability cannot be used by an attacker to gain access to user credentials. Affected products named by the advisory: SSO Client; SSO Agent.

CVE-2024-6592
Unclassified
Sep 25, 2024
High8.7WatchGuard

High [CVE-2024-6594] WatchGuard Firebox Single Sign-On Client Denial-of-Service

Improper Handling of Exceptional Conditions vulnerability in the WatchGuard Single Sign-On Client on Windows causes the client to crash while handling malformed commands. An attacker with network access to the client could create a denial of service condition for the Single Sign-On service by repeatedly issuing malformed commands. Affected product named by the advisory: SSO Client.

CVE-2024-6594
Unclassified
Sep 25, 2024
High8.6WatchGuard

High [CVE-2024-5974] Firebox Authenticated Buffer Overflow Vulnerability

A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with privileged management access to execute arbitrary code with system privileges on the firewall. This issue affects Fireware OS: from 11.9.6 through 12.10.3.

CVE-2024-5974
Firebox / Fireware
Jul 9, 2024
High8.6WatchGuard

High [CVE-2024-4944] Mobile VPN with SSL Local Privilege Escalation Vulnerability

A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands with elevated privileged.

CVE-2024-4944
Unclassified
Jul 9, 2024

← All vendors