CVE-2026-13086
9.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Summary
A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecated Mobile Security feature in WatchGuard Fireware OS allows an unauthenticated remote attacker to execute arbitrary code.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| WatchGuard | Fireware OS | 2025.0 < 2026.2.2 | affected |
| WatchGuard | Fireware OS | 12.0 < 12.12.2 | affected |
| WatchGuard | Fireware OS | 12.0 < 12.5.20 | affected |
Weaknesses
- CWE-121: CWE-121
- CWE-787: CWE-787
- CWE-798: CWE-798
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.