6.7mediumMedium
CVE-2026-4266
Watchguard Fireware
An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to the local filesystem through another vulnerability to execute arbitrary code in the context of the portald user. Note, this vulnerability does not affect Firebox platforms that do not support the Access Portal feature, including the T15 and T35.
Exploitation status
- A vendor advisory or patch reference has been published.
What the metrics mean
- It is requires local access to the machine.
- For an attacker who can reach it, no special conditions are needed to exploit it.
- To exploit it, an administrative account is needed.
- Beyond that, no action by a user is required.
Scoring
- CVSS
- 6.7 (v3.1)
- Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H- CVSS v4
- 8.4
- Weakness
- CWE-502
- Assigned by
- 5d1c2695-1a31-4499-88ae-e847036fd7e3
Dates
- Published
- 2026-03-30
- Last modified
- 2026-08-28
- Sources
- NVD
Affected products
- Watchguard Fireware2025.1 - 2026.2, 12.1 - 12.12
- Watchguard Firebox M295all versions
- Watchguard Firebox M395all versions
- Watchguard Firebox M495all versions
- Watchguard Firebox M595all versions
- Watchguard Firebox M695all versions
- Watchguard Firebox T115-Wall versions
- Watchguard Firebox T125all versions
- Watchguard Firebox T125-Wall versions
- Watchguard Firebox T145all versions
- Watchguard Firebox T145-Wall versions
- Watchguard Firebox T185all versions
As listed in the NVD configuration data. Not a statement about your estate.