CVE-2026-4266
Awaiting Analysis
Awaiting Analysis - Queue
Insecure Deserialization in WatchGuard Fireware OS Enables Code Execution
Publication date: 2026-03-30
Last updated on: 2026-03-30
Assigner: WatchGuard Technologies, Inc.
Description
Description
An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to the local filesystem through another vulnerability to execute arbitrary code in the context of the portald user.This issue affects Fireware OS: 12.1 through 12.11.8 and 2025.1 through 2026.1.2.
Note, this vulnerability does not affect Firebox platforms that do not support the Access Portal feature, including the T-15 and T-35.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| watchguard | fireware_os | From 12.1 (inc) to 12.11.8 (inc) |
| watchguard | fireware_os | From 2025.1 (inc) to 2026.1.2 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-502 | The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid. |