WatchGuard Technologies, Inc.

First CVE: May 16, 2024Active for: 2 years
62
CVEs Published
More CVEs Published than 63% of tracked CNAs
20.7
Avg CVEs / Year
More Avg CVEs / Year than 68% of tracked CNAs
6.9
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked CNAs
3.2%
In CISA KEV
Higher KEV Rate than 94% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by WatchGuard Technologies, Inc. as a CNA, 64.5% affect products that WatchGuard Technologies, Inc. develops as a vendor.

64.5%
35.5%
Self-reported: 40Third-party: 22

Of all the CVEs published that affect products developed by WatchGuard Technologies, Inc., 37.7% are self-published by WatchGuard Technologies, Inc. as a CNA.

37.7%
62.3%
Self-published: 40Published by other CNAs: 66

Trends Over Time

The number and severity of CVEs published by WatchGuard Technologies, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 16, 2024
2 years ago
Most Recent CVE
Jul 2, 2026
22 days ago

Top CVEs

All CVEs published by WatchGuard Technologies, Inc. as a CNA, regardless of affected vendor or product.

62 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the Mobile Use
Sep 17, 20259.898YESYES
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the Mobile Use
Dec 19, 20259.883YESNO
WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2. A remote unauthenticated attac
Jul 2, 20269.243NONO
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS networkd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted reque
Jul 2, 20268.639NONO
A null pointer dereference vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to create a denial-of-service (DoS) condition by sending specially cr
Jul 2, 20268.738NONO
WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image via the backup/restore feature. An authenticated administrator can exploit this vulnerab
Jul 2, 20268.637NONO
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command. Th
Jul 2, 20267.236NONO
A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated attacker to write arbitrary files on the Firebox's filesystem.
Jul 2, 20267.235NONO
A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows allows a local attacker to escalate their privileges to NT AUTHORITY\SYSTEM on t
Jul 2, 20267.835NONO
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker on the same local network segment to execute arbitrary code. This vulnerabi
Jul 2, 20267.735NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA62 CVEs
Severity distribution among all CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local13 (21.0%)
Network46 (74.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (3.2%)
Attack Complexity
Low60 (96.8%)
High2 (3.2%)
Unknown0 (0.0%)
User Interaction
None44 (71.0%)
Unknown0 (0.0%)
Required13 (21.0%)
Privileges Required
Low12 (19.4%)
High29 (46.8%)
None21 (33.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (62 CVEs).

CISA KEV
2 CVEs
3.2% of CVEs· 94th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
1.6% of CVEs· 83rd percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by WatchGuard Technologies, Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by WatchGuard Technologies, Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs