
WatchGuard Fireware: unauth root RCE from the local segment (CVE-2026-8247). admd stack overflow on Terminal Service agent login notifications. No auth. CVSS 4.0 7.7. Patch Firebox: 12.12.1 | 12.5.19 | 2026.2.1 https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00026
Post summary
The advisory discloses an unauthenticated root RCE vulnerability (CVE-2026-8247) in WatchGuard Fireware, provides CVSS score 7.7, and lists specific patch versions along with a vendor advisory link.


