CVE-2026-4266
Analyzed
Analyzed - Analysis Complete
Insecure Deserialization in WatchGuard Fireware OS Enables Code Execution
Vulnerability report for CVE-2026-4266, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-03-30
Last updated on: 2026-08-14
Assigner: WatchGuard Technologies, Inc.
Description
Description
An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to the local filesystem through another vulnerability to execute arbitrary code in the context of the portald user.
Note, this vulnerability does not affect Firebox platforms that do not support the Access Portal feature, including the T15 and T35.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| watchguard | fireware | From 2025.1 (inc) to 2026.2 (exc) |
| watchguard | fireware | From 12.1 (inc) to 12.12 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-502 | The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid. |