CVE-2026-13086
Deferred Deferred - Pending Action

Stack-Based Buffer Overflow in WatchGuard Fireware OS

Vulnerability report for CVE-2026-13086, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-09-03

Assigner: WatchGuard Technologies, Inc.

Description

A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecated Mobile Security feature in WatchGuard Fireware OS allows an unauthenticated remote attacker to execute arbitrary code.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-09-03
Generated
2026-09-17
AI Q&A
2026-08-28
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
watchguard fireware_os From 2025.0 (inc) to 2026.2.2 (exc)
watchguard fireware_os From 12.0 (inc) to 12.12.2 (exc)
watchguard fireware_os to 12.5.20 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stack-based buffer overflow in the epm service of WatchGuard Fireware OS, part of the deprecated Mobile Security feature. An unauthenticated remote attacker on a trusted network can send a crafted JSON-RPC request to trigger the overflow, overwrite the return address, and execute arbitrary code with root privileges. The lack of a stack canary and non-PIE binary make exploitation easier. Failed attempts may crash the epm process, causing a denial of service.

Detection Guidance

Check Fireware OS versions for affected releases (2025.0 to below 2026.2.2, 12.0 to below 12.12.2, or T15/T35 models below 12.5.20). Monitor epm service crashes or unexpected behavior on trusted network interfaces.

Impact Analysis

An attacker could gain full control of the affected system with root privileges, allowing them to install malware, steal data, or disrupt operations. Even failed attacks may cause service outages by crashing the epm process, requiring manual or automatic respawn to restore functionality.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR and HIPAA requirements for data protection and access control. A successful exploit may result in data breaches, triggering regulatory fines and compliance penalties.

Mitigation Strategies

Upgrade Fireware OS to patched versions: 2026.2.2, 12.12.2, or 12.5.20. Disable the deprecated Mobile Security feature if not in use. Restrict access to trusted network interfaces for the epm service.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13086. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart