CVE-2026-4266
MEDIUM WAF: Medium
CVSS 6.7
Published: 2026-03-30
CWE-502
An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to the local filesystem through another vulnerability to execute arbitrary code in the context of the portald user. Note, this vulnerability does not affect Firebox platforms that do not support the Access Portal feature, including the T15 and T35.
WAF Coverage Analysis
Insecure Deserialization
Medium WAF Coverage
OWASP: A08:2021 Software and Data Integrity Failures
944xxx - Java Attack
Affected Software
| Vendor | Product | Version |
|---|---|---|
| watchguard | fireware | 2025.1 - 2026.2 |
| watchguard | fireware | 12.1 - 12.12 |
References
- psirt.watchguard.com (Broken Link)
- www.watchguard.com (Vendor Advisory)