CVE-2026-1498Disclosure

LOWCVSS 7.0 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An LDAP Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensitive information from a connected LDAP authentication server through an exposed authentication or management web interface. This vulnerability may also allow a remote attacker to authenticate as an LDAP user with a partial identifier if they additionally have that user's valid passphrase.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-90

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-02-06)
  • 5 total mentions across 4 days

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-01-30: 1Mentions · 2026-02-04: 1Mentions · 2026-02-05: 1Mentions · 2026-02-06: 2Patch / Workaround · 2026-02-06: 1Technical Details · 2026-01-30: 1Technical Details · 2026-02-05: 1Technical Details · 2026-02-06: 201-3002-0402-0502-06
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-01-301
Disclosure1
2026-02-041
Disclosure1
2026-02-051
General1
2026-02-062
Disclosure1Patch1
Full discourse5 posts
  • Günter Born@etguenni
    General

    #WatchGuard #Firebox LDAP Injection Schwachstelle #cve-2026-1498 https://borncity.com/blog/2026/02/06/watchguard-firebox-fireware-os-ldap-injection-schwachstelle-cve-2026-1498/

    Post summary

    The post merely links to a blog entry about an LDAP injection flaw in WatchGuard Firebox (CVE‑2026‑1498) without further exploitation, patch, or detailed technical data.

    02010257
    2.6K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: #WatchGuard patched a high impact unauthenticated #LDAP injection vulnerability (#CVE-2026-1498) in WatchGuard #Fireware OS and a medium impact privilege escalation #PoE vulnerability #NCPVE-2025-0626 in its mobile VPN with IPSec client. #Patch #Patch #Patch

    Post summary

    WatchGuard has issued a patch for a high-impact unauthenticated LDAP injection vulnerability (CVE-2026-1498) and a medium-impact privilege escalation vulnerability (NCPVE-2025-0626) in its mobile VPN client.

    00001282
    7.2K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『This vulnerability may also allow a remote attacker to authenticate as an LDAP user with a partial identifier if they additionally have that user's valid passphrase.』 CVE-2026-1498 WatchGuard Firebox LDAP Injection https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00001

    Post summary

    The advisory discloses that a remote attacker could authenticate as an LDAP user using a partial identifier and a valid password, but provides no PoC, exploit code, or evidence of active exploitation.

    00000525
    6.7K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidad en productos WatchGuard ❗ CVE-2026-1498 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-watchguard-3/ https://t.co/b2NIJRifqv

    Post summary

    A new vulnerability (CVE-2026-1498) affecting WatchGuard products is announced, with additional information referenced via a link.

    00000142
    6.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1498 LDAP Injection in WatchGuard Fireware OS Enables Unauthorized Information Retrieval https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1498

    Post summary

    An announcement of CVE-2026-1498, describing an LDAP injection in WatchGuard Fireware OS that permits unauthorized information retrieval, without any mention of PoCs, exploits, or mitigation steps.

    0000066
    4.0K followersView on X

Explore more