CVE-2026-3343

Summary

A reflected cross-site scripting (XSS) vulnerability in the Fireware OS Web UI enabled execution of malicious JavaScript in the context of an authenticated management user's browser when they click on a specially crafted link.

Affected Software

VendorProductVersion RangeStatus
WatchGuardFireware OS2025.1 < 2026.1.2affected
WatchGuardFireware OS12.7 < 12.11.8affected

Weaknesses

  • CWE-79: CWE-79

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References