Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-4315: CWE-352 in WatchGuard Fireware OSCVE-2026-4315
0

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WatchGuard Fireware OS WebUI that could allow a remote attacker to cause a denial-of-service (DoS) condition by tricking an authenticated administrator into visiting a malicious web page. This vulnerability affects multiple versions of Fireware OS, specifically versions 11.8 through 11.12.4+541730, 12.0 through 12.11.8, and 2025.1 through 2026.1.2. The issue does not impact confidentiality or integrity but can disrupt availability of the Web UI.

Join the discussion
CVE-2026-3987: CWE-22 in WatchGuard Fireware OSCVE-2026-3987
0

A path traversal vulnerability exists in the Fireware OS Web UI on WatchGuard Firebox systems. This flaw may allow a privileged authenticated remote attacker to execute arbitrary code with elevated system process privileges. The vulnerability affects Fireware OS versions from 12.6.1 up to and including 12.11.8, and from 2025.1 up to and including 2026.1.2. The CVSS 3.1 base score is 7.2, indicating a high severity issue.

Join the discussion
CVE-2026-13368: CWE-416 in WatchGuard Fireware OSCVE-2026-13368
0

WatchGuard Fireware OS has a race condition vulnerability that leads to a use-after-free in LDAP authentication for Mobile User VPN with IKEv2. This flaw allows a remote unauthenticated attacker to execute arbitrary code in the context of the iked process on affected Fireboxes configured with external LDAP authentication. The vulnerability affects Fireware OS versions 11.0 through 11.12.4_Update1, 12.0 through 12.12, and 2025.1 through 2026.2. It has a CVSS 3.1 score of 8.1, indicating critical severity.

Join the discussion
CVE-2026-13050: CWE-787 in WatchGuard Fireware OSCVE-2026-13050
0

An out-of-bounds write vulnerability exists in the WatchGuard Fireware OS networkd process that could allow an authenticated privileged user to execute arbitrary code via specially crafted requests to the Management Web UI. This affects Fireware OS versions 11.8 through 11.12.4_Update1, 12.0 through 12.12, and 2025.1 through 2026.2. The vulnerability has a high severity rating with a CVSS score of 7.2.

Join the discussion
CVE-2025-6947: CWE-79 in WatchGuard Fireware OSCVE-2025-6947
0

CVE-2025-6947 is a stored cross-site scripting (XSS) vulnerability in the management interface of WatchGuard Firebox appliances, specifically via the SIP Proxy configuration. An authenticated attacker with administrator privileges can exploit this flaw to execute arbitrary JavaScript code in the management interface of other users. The vulnerability affects Fireware OS version 12.0 and has a medium severity rating with a CVSS 4.8 score.

Join the discussion
CVE-2025-1071: CWE-79 in WatchGuard Fireware OSCVE-2025-1071
0

CVE-2025-1071 is a stored cross-site scripting (XSS) vulnerability in WatchGuard Fireware OS affecting the spamBlocker module. It requires an authenticated administrator session on a locally managed Firebox device. The vulnerability affects Fireware OS versions from 12.0 through 12.5.12+701324 and from 12.6 through 12.11. The CVSS score is 4.8 (medium severity).

Join the discussion
CVE-2024-5974: CWE-120 in WatchGuard Fireware OSCVE-2024-5974
0

A buffer overflow vulnerability exists in WatchGuard Fireware OS that could allow an authenticated remote attacker with privileged management access to execute arbitrary code with system privileges on the firewall. The affected versions range from 11.9.6 through 12.10.3. This vulnerability has a high severity score of 7.2 and impacts confidentiality, integrity, and availability of the system.

Join the discussion
CVE-2025-4804: CWE-79 in WatchGuard Fireware OSCVE-2025-4804
0

CVE-2025-4804 is a stored cross-site scripting (XSS) vulnerability in WatchGuard Fireware OS affecting the spamBlocker module. It requires an authenticated administrator session on a locally managed Firebox device. The vulnerability affects Fireware OS versions from 12.0 through 12.11.1. There is no information about an available patch or official remediation at this time.

Join the discussion
CVE-2025-1239: CWE-79 in WatchGuard Fireware OSCVE-2025-1239
0

CVE-2025-1239 is a stored cross-site scripting (XSS) vulnerability in the management interface of WatchGuard Firebox appliances, specifically via the Blocked Sites list. An authenticated administrator can exploit this flaw to execute arbitrary JavaScript code in the management interface of other users. The vulnerability has a medium severity rating with a CVSS 4.8 score. No official patch or vendor advisory is currently provided, and no known exploits are reported in the wild.

Join the discussion
CVE-2025-1239: CWE-79 in WatchGuard Fireware OSCVE-2025-1239
0

A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the Blocked Sites list. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface of another management user.

Join the discussion

Showing 1 to 10 of 12 results

Filters:Package: pkg:github/watchguard/fireware-os
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses