WatchGuard Patches 21 Fireware OS Flaws
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
WatchGuard fixed 21 vulnerabilities in Fireware OS, including unauthenticated RCE and DoS bugs in VPN, DHCP and management services, up to CVSS 9.3.
NCSC-NL has published an advisory summarizing 21 vulnerabilities that WatchGuard has patched in Fireware OS, the firmware running on Firebox security appliances, along with related components (WatchGuard Access Points, WatchGuard Dimension). The flaws span a wide range of weakness classes including path traversal, stack-based buffer overflow, code injection, integer underflow, NULL pointer dereference, deserialization of untrusted data, improper authorization and a libxml2 out-of-bounds read. Several of the most serious issues require no authentication and only network access: a stack-based buffer overflow in the DHCP fingerprinting daemon can yield remote code execution or a crash, a NULL pointer dereference in NetFlow packet processing can crash the device remotely, and integer underflow flaws in the IKE/IKEv2 daemons allow unauthenticated denial-of-service. A code-injection vulnerability in the BOVPN Over TLS client configuration lets an attacker who controls the remote VPN server execute commands with root privileges on the Firebox itself — a notable risk for organizations using third-party or less-trusted VPN peers. Other issues require some level of authentication: a malicious SAML SSO session file can lead to arbitrary code execution for an attacker with write access, authenticated admins can read arbitrary files via path traversal in the WebUI Management Agent, and low-privileged authenticated users can escalate access to Mobile VPN with SSL or to unauthorized web applications through flaws in the Access Portal and its reverse proxy.
Additional issues affect WatchGuard Access Points (OS command injection via an internal API) and WatchGuard Dimension (CSRF allowing unauthorized database snapshot creation). CVSS scores range widely, with several in the 8–9.3 band reflecting significant impact (RCE, privileged command execution, file disclosure), though NCSC-NL does not indicate any of the 21 CVEs are being exploited in the wild. WatchGuard has released firmware updates addressing all listed CVEs; defenders running Fireware OS, Firebox appliances, WatchGuard Access Points, or Dimension should prioritize patching, particularly for the unauthenticated network-facing issues (DHCP daemon, NetFlow, IKE/IKEv2) and the VPN-related code injection, and review SAML SSO and Access Portal configurations for unauthorized access indicators.
No indicators of compromise, threat actor attribution, or active exploitation are described in this advisory — it is a vendor patch bulletin relayed by the Dutch national CERT. Defenders should treat this as a patch-management priority rather than an active-incident response action, while still monitoring for anomalous VPN server behavior, unexpected SAML session files, and crashes in DHCP/NetFlow/IKE services as potential exploitation attempts.
Mentioned in this report
Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0404.html
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 10,887 reports from 149 sources, 449 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs