| Critical |
WGSA-2024-00012 |
OpenSSH regreSSHion (CVE-2024-6387) |
CVE-2024-6387 |
|
| Critical |
WGSA-2024-00014 |
WatchGuard Firebox Single Sign-On Agent Protocol Authorization Bypass |
CVE-2024-6592 |
|
| Critical |
WGSA-2024-00015 |
WatchGuard SSO Agent Telnet Authentication Bypass |
CVE-2024-6593 |
|
| Critical |
WGSA-2024-00007 |
XZ Utils supply chain compromise (CVE-2024-3094) |
CVE-2024-3094 |
|
| Critical |
WGSA-2026-00023 |
WatchGuard Firebox Race Condition and Use-After-Free in Mobile VPN with IKEv2 LDAP Authentication |
CVE-2026-13368 |
|
| Critical |
WGSA-2024-00004 |
Ivanti Connect Secure and Ivanti Policy Secure Gateway Vulnerabilities |
CVE-2023-46805, CVE-2024-21887, CVE-2024-21888, CVE-2024-21893 |
|
| Critical |
WGSA-2023-00009 |
Apache Struts Remote Code Execution Vulnerability (CVE-2023-50164) |
CVE-2023-50164 |
|
| Critical |
WGSA-2023-00008 |
Heap Buffer Overflow in libwebp WebP Codec |
CVE-2023-4863 |
|
| Critical |
WGSA-2025-00027 |
WatchGuard Firebox iked Out of Bounds Write Vulnerability |
CVE-2025-14733 |
|
| Critical |
WGSA-2022-00016 |
Firebox Authenticated Stack Overflow Vulnerability va CLI Interface |
CVE-2022-25362 |
|
| Critical |
WGSA-2022-00015 |
Firebox Unauthenticated Buffer Overflow Vulnerability |
CVE-2022-31789 |
|
| Critical |
WGSA-2022-00010 |
Java Spring Framework RCE aka Spring4Shell (CVE-2022-22965) |
CVE-2022-22965 |
|
| Critical |
WGSA-2021-00003 |
Log4j2 Remote Code Execution Vulnerability aka Log4Shell (CVE-2021-44228) |
CVE-2021-44228 |
|
| Critical |
WGSA-2025-00015 |
WatchGuard Firebox iked Out of Bounds Write Vulnerability |
CVE-2025-9242 |
|
| Critical |
WGSA-2022-00002 |
Firebox Unauthenticated Remote Code Execution Vulnerability |
CVE-2022-26318 |
|
| Critical |
WGSA-2022-00004 |
Firebox Unauthenticated Arbitrary FIle Delete Vulnerability |
CVE-2022-25361 |
|
| High |
WGSA-2026-00028 |
WatchGuard Firebox Arbitrary File Write via Path Traversal in Management Web UI |
CVE-2026-13054 |
|
| High |
WGSA-2026-00021 |
WatchGuard Firebox wgagent Out of Bounds Write Vulnerability |
CVE-2026-13384 |
|
| High |
WGSA-2026-00026 |
WatchGuard Firebox admd Out of Bounds Write Vulnerability |
CVE-2026-8247 |
|
| High |
WGSA-2026-00027 |
WatchGuard Mobile VPN with SSL Windows Client Local Privilege Escalation |
CVE-2026-13079 |
|
| High |
WGSA-2026-00029 |
WatchGuard Firebox networkd Out of Bounds Write Vulnerability |
CVE-2026-13050 |
|
| High |
WGSA-2026-00020 |
WatchGuard Firebox ikestubd Out of Bounds Write Vulnerability |
CVE-2026-13383 |
|
| High |
WGSA-2026-00030 |
WatchGuard Firebox Authenticated Out of Bounds Write in Management CLI Command Handler |
CVE-2026-13053 |
|
| High |
WGSA-2026-00022 |
WatchGuard Firebox Firmware Image Validation Bypass in WatchGuard Fireware OS |
CVE-2026-13722 |
|
| High |
WGSA-2026-00024 |
WatchGuard Firebox iked Null Pointer Dereference |
CVE-2026-13084 |
|
| High |
WGSA-2026-00013 |
WatchGuard Agent on Windows Local Privilege Escalation to SYSTEM via Chained Agent Service Vulnerabilities |
CVE-2026-6787, CVE-2026-6788 |
|
| High |
WGSA-2026-00010 |
Stack-based Buffer Overflow in WatchGuard Agent Discovery Service on Windows Causes Denial of Service - Variant A |
CVE-2026-41287 |
|
| High |
WGSA-2026-00011 |
Stack-based Buffer Overflow in WatchGuard Agent Discovery Service on Windows Causes Denial of Service - Variant B |
CVE-2026-41286 |
|
| High |
WGSA-2026-00012 |
WatchGuard Agent on Windows Privilege Escalation Vulnerability |
CVE-2026-41288 |
|
| High |
WGSA-2026-00009 |
WatchGuard Firebox Arbitrary File Write via Path Traversal in Fireware Web UI |
CVE-2026-3987 |
|
| High |
WGSA-2026-00008 |
Multiple Vulnerabilities in AppArmor AKA CrackArmor |
CVE-2026-23268, CVE-2026-23269 |
|
| High |
WGSA-2026-00006 |
WatchGuard Firebox Cross-Site Request Forgery (CSRF) in Fireware Web UI |
CVE-2026-4315 |
|
| High |
WGSA-2026-00007 |
WatchGuard Firebox Insecure Deserialization in Fireware Access Portal |
CVE-2026-4266 |
|
| High |
WGSA-2026-00003 |
WatchGuard Firebox Out of Bounds Write Vulnerability |
CVE-2026-3342 |
|
| High |
WGSA-2026-00001 |
WatchGuard Firebox LDAP Injection |
CVE-2026-1498 |
|
| High |
WGSA-2025-00019 |
WatchGuard Firebox Authenticated Out of Bounds Write in Management CLI IPSec Configuration |
CVE-2025-12195 |
|
| High |
WGSA-2025-00020 |
WatchGuard Firebox Authenticated Out of Bounds Write in Management CLI Ping Command |
CVE-2025-12196 |
|
| High |
WGSA-2025-00017 |
WatchGuard Firebox Authenticated Out of Bounds Write in certd |
CVE-2025-12026 |
|
| High |
WGSA-2025-00025 |
WatchGuard Firebox XPath Injection Vulnerability in Web CGI |
CVE-2025-1545 |
|
| High |
WGSA-2025-00018 |
WatchGuard Firebox iked Memory Corruption Vulnerability |
CVE-2025-11838 |
|
| High |
WGSA-2025-00013 |
WatchGuard Firebox Authenticated Stack Overflow in Certificate Request Command |
CVE-2025-1547 |
|
| High |
WGSA-2025-00010 |
WatchGuard Firebox Leftover Debug Code Vulnerability |
CVE-2025-4106 |
|
| High |
WGSA-2025-00008 |
WatchGuard Mobile VPN with SSL Local Privilege Escalation |
CVE-2025-1910 |
|
| High |
WGSA-2019-00002 |
Inferring and hijacking VPN-tunneled TCP connections |
CVE-2019-14899 |
|
| High |
WGSA-2019-00001 |
TCP SACK PANIC – Kernel Vulnerabilities |
CVE-2019-11477, CVE-2019-11478, CVE-2019-11479 |
|
| High |
WGSA-2021-00002 |
MacOS SSL VPN Privilege Escalation Vulnerability |
|
|
| High |
WGSA-2021-00005 |
Firebox WebUI Business Logic Vulnerability |
|
|
| High |
WGSA-2021-00004 |
Firebox Management Privilege Escallation Vulnerability |
CVE-2022-23176 |
|
| High |
WGSA-2022-00011 |
OpenSSL Certificate Processing DoS Vulnerability (CVE-2022-0778) |
CVE-2022-0778 |
|
| High |
WGSA-2024-00005 |
lighttpd denial of service vulnerability (CVE-2022-41556) |
CVE-2022-41556 |
|