Vulnerabilities in WatchGuard

62 results
Vexday analysis

WatchGuard acumula 62 vulnerabilidades no histórico, com 21 publicadas nos últimos 90 dias indicando ritmo elevado de descobertas; cinco são críticas e duas estão sob exploração ativa em campo. A fraqueza dominante (CWE-79, injeção de código) sugere falhas sistemáticas em validação de entrada, exigindo priorização imediata de patches para as duas vulnerabilidades em KEV e revisão ampla da postura de segurança do fornecedor.

CVE-2026-41287HIGHStack-based Buffer Overflow in WatchGuard Agent Discovery Service on Windows Causes Denial of Service - Variant AEPSS 0.2%CVE-2026-8247HIGHWatchGuard Firebox admd Out of Bounds Write VulnerabilityEPSS 0.2%CVE-2026-3343MEDIUMWatchGuard Firebox Reflected Cross-Site-Scripting (XSS) Vulnerability in Fireware Web UIEPSS 0.2%CVE-2024-8424HIGHWatchGuard Endpoint Protection Privilege Escalation in PSANHost Enables Arbitrary File Delete as SYSTEMEPSS 0.2%CVE-2025-13938MEDIUMWatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Autotask Technology Integration ConfigurationEPSS 0.2%CVE-2025-13937MEDIUMWatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in ConnectWise Technology Integration ConfigurationEPSS 0.2%CVE-2025-13936MEDIUMWatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Tigerpaw Technology Integration ConfigurationEPSS 0.2%CVE-2025-13939MEDIUMWatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Gateway Wireless ControllerEPSS 0.2%CVE-2026-13377MEDIUMWatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in SIP Proxy ConfigurationEPSS 0.2%CVE-2026-13374MEDIUMWatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in ConnectWise Technology Integration ConfigurationEPSS 0.2%CVE-2026-13376MEDIUMWatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in spamBlocker ModuleEPSS 0.2%CVE-2026-13375MEDIUMWatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Autotask Technology Integration ConfigurationEPSS 0.2%CVE-2026-13373MEDIUMWatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Tigerpaw Technology Integration ConfigurationEPSS 0.2%CVE-2025-2782MEDIUMWatchGuard Terminal Services Agent Local Privilege Escalation via Non-Standard Installation DirectoryEPSS 0.1%CVE-2026-13079HIGHWatchGuard Mobile VPN with SSL Windows Client Local Privilege EscalationEPSS 0.1%CVE-2025-1549MEDIUMWatchGuard Mobile VPN with SSL Local Privilege EscallationEPSS 0.1%CVE-2026-13728MEDIUMWatchGuard Firebox Hardcoded Fallback Encryption Key in Access Portal Resource Credential DatabaseEPSS 0.1%CVE-2025-2781MEDIUMWatchGuard Mobile VPN with SSL Local Privilege Escalation via Non-Standard Installation DirectoryEPSS 0.1%CVE-2026-6788HIGHUncontrolled search path in PluginLauncher allows SYSTEM code execution in WatchGuard AgentEPSS 0.1%CVE-2025-13940MEDIUMWatchGuard Firebox Boot Time System Integrity Check BypassEPSS 0.1%