CVE-2026-13053Disclosure(watchguard / firebox_m270)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch watchguard firebox_m270 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • firebox_m270
  • firebox_m290
  • firebox_m295
  • firebox_m370

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 8 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 6 mentions (2026-07-03); latest day: 1
  • 8 total mentions across 3 days

Affected systems

Vendors
Products
firebox_m270firebox_m290firebox_m295firebox_m370firebox_m390firebox_m395firebox_m440firebox_m4600firebox_m470firebox_m4800

1 version affected across 39 products

Deep dive

Activity timeline8 mentions / 3d
02356Mentions · 2026-07-03: 6Mentions · 2026-07-10: 1Mentions · 2026-08-03: 1Patch / Workaround · 2026-07-03: 4Patch / Workaround · 2026-07-10: 1Technical Details · 2026-07-03: 6Technical Details · 2026-07-10: 1Technical Details · 2026-08-03: 107-0307-1008-03
Signal classification2 categories
Disclosure
450.0%
Patch
450.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-07-036
Disclosure3Patch3
2026-07-101
Patch1
2026-08-031
Disclosure1
Full discourse8 posts
  • iototsecnews@iototsecnews
    Patch

    WatchGuard Firebox OS の脆弱性 CVE-2026-13053/13050/13054 が FIX:任意のコード実行の恐れ https://iototsecnews.jp/2026/07/03/multiple-watchguard-firebox-os-vulnerabilities-enable-arbitrary-code-execution-attacks/ ネットワークの防御を担う機器 WatchGuard Firebox の制御ソフトにおいて、ログイン後の管理画面などから不正な命令を実行されてしまう複数の高深刻度な脆弱性 CVE-2026-13053/CVE-2026-13050/CVE-2026-13054 が見つかりました。この問題の背景には、管理用のコマンド入力を処理する際のデータ検証や、ファイルの書き込み経路を制限する仕組みの不備があります。もし管理者情報の漏洩などを機に悪用されると、機器の重要なシステムファイルを書き換えられて通信制御を完全に奪われるといった甚大な被害が生じる恐れがあります。確実な対応策として、まずは稼働中の Fireware OS のバージョンを確認し、最新の修正パッチを速やかに適用してください。 #CVE202613050 #CVE202613053 #CVE202613054 #FireboxOS #Vulnerability #WatchGuard

    Post summary

    WatchGuard Firebox OS suffers from three high‑severity CVEs (CVE‑2026‑13053, ‑13050, ‑13054) that enable arbitrary code execution; vendors have released patches, and users are advised to update promptly.

    00110143
    500 followersView on X
  • SystemTek - Technology news website@SystemTek_UK
    Disclosure

    WatchGuard FireWare OS cli Token Parser Stack-based Buffer Overflow Remote Code Execution Vulnerability (CVE-2026-13053) https://www.systemtek.co.uk/2026/08/watchguard-fireware-os-cli-token-parser-stack-based-buffer-overflow-remote-code-execution-vulnerability-cve-2026-13053/ via @SystemTek_UK

    Post summary

    The tweet announces a newly identified stack‑based buffer overflow vulnerability (CVE‑2026‑13053) that leads to remote code execution in WatchGuard FireWare OS, and links to an article that likely details the exploit.

    0000070
    1.8K followersView on X
  • ADK Cyber@ADKCyber
    Patch

    WatchGuard Fireware OS CLI has high-severity CVE-2026-13053 (CVSS 8.6) allowing code execution by authenticated admins. Apply updates promptly: https://nvd.nist.gov/vuln/detail/CVE-2026-13053 via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/DoEN1gTXZE

    Post summary

    The tweet highlights the high‑severity CVE‑2026‑13053 in WatchGuard Fireware OS CLI, warns of code execution by authenticated admins, and urges users to apply official updates promptly.

    0000062
    92 followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    WatchGuard's Firebox OS has critical vulnerabilities (CVE-2026-13053, CVE-2026-13050, CVE-2026-13054) allowing authenticated attackers to execute arbitrary code. Affected versions span 11.0 through 12.12 and 2025.1 through 2026.2. Immediate patching to versions 2026.2.1 or 12.12.1 is essential to secure devices. #CyberSecurity #WatchGuard #Firebox #Vulnerabilities #PatchNow #NetworkSecurity https://thedailytechfeed.com/critical-vulnerabilities-in-watchguard-firebox-os-allow-arbitrary-code-execution/

    Post summary

    WatchGuard’s Firebox OS suffers from three critical CVEs that allow authenticated attackers to run arbitrary code; the advisory stresses immediate patching to the specified secure releases.

    0000056
    470 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 HIGH - WatchGuard Fireware OS CLI out-of-bounds write leading to code execution (CVE-2026-13053) CVE-2026-13053 is an out-of-bounds write in the WatchGuard Fireware OS command-line interface (CLI) that impacts multiple Fireware release trains. The root cause is a memory corruption flaw (out-of-bounds write) triggered by improper bounds checking while handling crafted CLI input. An attacker must have authenticated, privileged CLI access and can exploit it by issuing a specially crafted command that overwrites memory in the CLI process. If exploited, this can lead to arbitrary code execution on the appliance, enabling full device compromise, configuration tampering, and potential pivoting into internal networks. 👉 Affected: WatchGuard Fireware OS 11.0–11.12.4_Update1, 12.0–12.12, 2025.1–2026.2 | Upgrade to a vendor-fixed release beyond these versions (no fixed version specified — treat as suspicious until confirmed)

    Post summary

    The post details a new out‑of‑bounds write vulnerability (CVE‑2026‑13053) in WatchGuard Fireware OS CLI, recommends upgrading to a patched release, and provides technical specifics but no PoC or evidence of active exploitation.

    0000083
    236 followersView on X
  • TECHEPAGES@techepages
    Patch

    🔥 Multiple WatchGuard Firebox OS vulnerabilities enable arbitrary code execution attacks 🔹 3 high-severity flaws (CVE-2026-13053, -13050, -13054), all scored 8.6 CVSS v4.0 🔹 Authenticated attackers can run arbitrary code & write files via CLI and Web UI 🔹 Affects hardware, virtual & cloud Fireboxes — Fireware 11.0 through 2026.2 🔹 No workarounds — update to 2026.2.1 / 12.12.1 & lock down management access

    Post summary

    The notice highlights three high‑severity CVEs in WatchGuard Firebox OS, offering no workarounds other than applying the latest updates and tightening management access.

    0000046
    23 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-13053 An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CL… https://www.cve.org/CVERecord?id=CVE-2026-13053 ----- Traducción: CVE-2026-13053 Un … http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-13053, describing an out‑of‑bounds write in WatchGuard Fireware OS's CLI that could allow authenticated privileged users to execute arbitrary code.

    0000040
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-13053 An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CL… https://www.cve.org/CVERecord?id=CVE-2026-13053

    Post summary

    The CVE describes an out‑of‑bounds write in WatchGuard Fireware OS’s CLI that permits an authenticated privileged user to execute arbitrary code via a specially crafted command.

    00000704
    57.7K followersView on X
CPE platform detail39 entries

39 of 39 entries

PartVendorProductVersionTarget SWTarget HW
HWwatchguardfirebox_m270---
HWwatchguardfirebox_m290---
HWwatchguardfirebox_m295---
HWwatchguardfirebox_m370---
HWwatchguardfirebox_m390---
HWwatchguardfirebox_m395---
HWwatchguardfirebox_m440---
HWwatchguardfirebox_m4600---
HWwatchguardfirebox_m470---
HWwatchguardfirebox_m4800---
HWwatchguardfirebox_m495---
HWwatchguardfirebox_m5600---
HWwatchguardfirebox_m570---
HWwatchguardfirebox_m5800---
HWwatchguardfirebox_m590---
HWwatchguardfirebox_m595---
HWwatchguardfirebox_m670---
HWwatchguardfirebox_m690---
HWwatchguardfirebox_m695---
HWwatchguardfirebox_nv5---
HWwatchguardfirebox_t115-w---
HWwatchguardfirebox_t125---
HWwatchguardfirebox_t125-w---
HWwatchguardfirebox_t145---
HWwatchguardfirebox_t145-w---
HWwatchguardfirebox_t15---
HWwatchguardfirebox_t185---
HWwatchguardfirebox_t20---
HWwatchguardfirebox_t25---
HWwatchguardfirebox_t35---
HWwatchguardfirebox_t40---
HWwatchguardfirebox_t45---
HWwatchguardfirebox_t55---
HWwatchguardfirebox_t70---
HWwatchguardfirebox_t80---
HWwatchguardfirebox_t85---
HWwatchguardfireboxcloud---
HWwatchguardfireboxv---
OSwatchguardfireware---

Explore more