CVE-2026-13728
Analyzed
Analyzed - Analysis Complete
Hard-Coded Encryption Key in WatchGuard Fireware OS
Vulnerability report for CVE-2026-13728, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-07-03
Last updated on: 2026-08-10
Assigner: WatchGuard Technologies, Inc.
Description
Description
In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved credentials for Access Portal resources.
This vulnerability does not affect devices that do not support the Access Portal feature or standalone Fireboxes not deployed in a FireCluster.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| watchguard | fireware | From 12.1 (inc) to 12.12.1 (exc) |
| watchguard | fireware | From 2025.1 (inc) to 2026.2.1 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-798 | The product contains hard-coded credentials, such as a password or cryptographic key. |