CVE-2026-78008

Summary

A buffer overflow vulnerability in the WatchGuard Fireware OS Management Web UI allows an authenticated administrator with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic.

Affected Software

VendorProductVersion RangeStatus
WatchGuardFireware OS2025.0 < 2026.2.2affected
WatchGuardFireware OS12.0 < 12.12.2affected
WatchGuardFireware OS12.0 < 12.5.20affected

Weaknesses

  • CWE-787: CWE-787

Workarounds

Administrators should not expose the Firebox's management interfaces to untrusted network locations. See our Firebox Remote Management Best Practices (https://techsearch.watchguard.com/KB?type=Article&amp;SFDCID=kA10H000000XeAtSAK&amp;lang=en_US) KB article for guidance on how to secure remote management to a Firebox.

References