CVE-2026-13079: WatchGuard Fireware
High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.
A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows allows a local attacker to escalate their privileges to NT AUTHORITY\SYSTEM on the machine where the client is installed. This issue affects the Mobile VPN with SSL client for Windows up to and including 2026.2.
Affected products
- WatchGuard Fireware: from 12.0.0, before 12.12.1 (fixed in 12.12.1); from 2025.1, before 2026.2.1 (fixed in 2026.2.1); from 12.5, up to and including 12.5.18
- WatchGuard Mobile VPN With SSL: before 2026.2.1 (fixed in 2026.2.1)
Published 2026-07-03. Last modified 2026-08-10.