Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

WatchGuard Technologies, Inc.

First CVE: Oct 20, 2000Active for: 26 yearsTotal CVEs: 106
68.1
VTI Score
TOP TARGET

WatchGuard Technologies maintains a moderately broad portfolio of network security appliances, particularly its Fireware operating system and Firebox firewall product line, which are widely deployed in enterprise and mid-market environments as perimeter defense and threat-prevention systems. Vulnerabilities affecting the vendor carry a meaningful share reaching serious severity and have an elevated tendency to acquire public exploit code, reflecting the appeal of internet-facing security appliances as high-value targets. The recurring exposure centers on Fireware and its Firebox implementations across form factors and throughput classes, and concentrates in weakness classes including input validation, cross-site scripting, and out-of-bounds writes that are characteristic of appliance firmware and web-management interfaces. Defenders should prioritize internet-exposed instances and track this vendor's firmware releases for timely patching; live exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
106
Total CVEs
More Total CVEs than 99% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
3.8%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by WatchGuard Technologies, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 20, 2000
25 years ago
Most Recent CVE
Jul 2, 2026
22 days ago

Self-Reporting Analysis

Of all the CVEs published by WatchGuard Technologies, Inc. as a CNA, 64.5% affect products that WatchGuard Technologies, Inc. develops as a vendor.

64.5%
35.5%
Self-reported: 40 (64.5%)
Third-party: 22 (35.5%)

Of all the CVEs published that affect products developed by WatchGuard Technologies, Inc., 37.7% are self-published by WatchGuard Technologies, Inc. as a CNA.

37.7%
62.3%
Self-published: 40 (37.7%)
Other CNAs: 66 (62.3%)

Products(114 total)

Top CVEs

Signals from CVEs in this vendor scope (106 CVEs).

106 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-9242CRITICAL
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the Mobile Use
Sep 17, 20259.898YESYES
CVE-2022-26318CRITICAL
On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12
Mar 4, 20229.896YESYES
CVE-2025-14733CRITICAL
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the Mobile Use
Dec 19, 20259.883YESNO
CVE-2022-23176HIGH
WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access.
Feb 24, 20228.872YESNO
CVE-2015-5453MEDIUM
Watchguard XCS 9.2 and 10.0 before build 150522 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the id parameter to ADMIN/mailqueue.spl.
Jul 8, 20156.565NOYES
CVE-2018-10575CRITICAL
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Hardcoded credentials exist for an unprivileged SSH account with a shell of /bi
Apr 30, 20189.843NOYES
CVE-2013-6021HIGH
Buffer overflow in WGagent in WatchGuard WSM and Fireware before 11.8 allows remote attackers to execute arbitrary code via a long sessionid value in a cookie.
Oct 19, 20139.340NOYES
CVE-2018-10577HIGH
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10. File upload functionality allo
May 2, 20188.838NOYES
CVE-2026-13053HIGH
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command. Th
Jul 2, 20267.236NONO
CVE-2016-3943HIGH
Panda Endpoint Administration Agent before 7.50.00, as used in Panda Security for Business products for Windows, uses a weak ACL for the Panda Security/WaAgent directory and sub-di
Apr 18, 20167.836NOYES
View all 106 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products106 CVEs
44%
46%
8%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local19 (17.9%)
Network57 (53.8%)
Unknown27 (25.5%)
Physical0 (0.0%)
Adjacent Network3 (2.8%)
Attack Complexity
Low77 (72.6%)
High2 (1.9%)
Unknown27 (25.5%)
User Interaction
None59 (55.7%)
Unknown27 (25.5%)
Required20 (18.9%)
Privileges Required
Low26 (24.5%)
High21 (19.8%)
None32 (30.2%)
Unknown27 (25.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (106 CVEs).

CISA KEV
4 CVEs
3.8% of CVEs· 99th percentile
Metasploit
2 CVEs
1.9% of CVEs· 97th percentile
Nuclei
2 CVEs
1.9% of CVEs· 95th percentile
ExploitDB
13 CVEs
12.3% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by WatchGuard Technologies, Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by WatchGuard Technologies, Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For WatchGuard Technologies, Inc.'s Products

View all 5 CNAs →

Top CWEs