WatchGuard Technologies maintains a moderately broad portfolio of network security appliances, particularly its Fireware operating system and Firebox firewall product line, which are widely deployed in enterprise and mid-market environments as perimeter defense and threat-prevention systems. Vulnerabilities affecting the vendor carry a meaningful share reaching serious severity and have an elevated tendency to acquire public exploit code, reflecting the appeal of internet-facing security appliances as high-value targets. The recurring exposure centers on Fireware and its Firebox implementations across form factors and throughput classes, and concentrates in weakness classes including input validation, cross-site scripting, and out-of-bounds writes that are characteristic of appliance firmware and web-management interfaces. Defenders should prioritize internet-exposed instances and track this vendor's firmware releases for timely patching; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by WatchGuard Technologies, Inc. over time
Of all the CVEs published by WatchGuard Technologies, Inc. as a CNA, 64.5% affect products that WatchGuard Technologies, Inc. develops as a vendor.
Of all the CVEs published that affect products developed by WatchGuard Technologies, Inc., 37.7% are self-published by WatchGuard Technologies, Inc. as a CNA.
Signals from CVEs in this vendor scope (106 CVEs).
106 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-9242CRITICAL An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the Mobile Use | Sep 17, 2025 | 9.8 | 98 | YES | YES |
CVE-2022-26318CRITICAL On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12 | Mar 4, 2022 | 9.8 | 96 | YES | YES |
CVE-2025-14733CRITICAL An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the Mobile Use | Dec 19, 2025 | 9.8 | 83 | YES | NO |
CVE-2022-23176HIGH WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access. | Feb 24, 2022 | 8.8 | 72 | YES | NO |
CVE-2015-5453MEDIUM Watchguard XCS 9.2 and 10.0 before build 150522 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the id parameter to ADMIN/mailqueue.spl. | Jul 8, 2015 | 6.5 | 65 | NO | YES |
CVE-2018-10575CRITICAL An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Hardcoded credentials exist for an unprivileged SSH account with a shell of /bi | Apr 30, 2018 | 9.8 | 43 | NO | YES |
CVE-2013-6021HIGH Buffer overflow in WGagent in WatchGuard WSM and Fireware before 11.8 allows remote attackers to execute arbitrary code via a long sessionid value in a cookie. | Oct 19, 2013 | 9.3 | 40 | NO | YES |
CVE-2018-10577HIGH An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10. File upload functionality allo | May 2, 2018 | 8.8 | 38 | NO | YES |
CVE-2026-13053HIGH An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command.
Th | Jul 2, 2026 | 7.2 | 36 | NO | NO |
CVE-2016-3943HIGH Panda Endpoint Administration Agent before 7.50.00, as used in Panda Security for Business products for Windows, uses a weak ACL for the Panda Security/WaAgent directory and sub-di | Apr 18, 2016 | 7.8 | 36 | NO | YES |
Signals from CVEs in this vendor scope (106 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by WatchGuard Technologies, Inc..
Media articles that mention a CVE ID that affects a product developed by WatchGuard Technologies, Inc. — matched by CVE ID, not by vendor name.