CVE-2026-3343: WatchGuard Fireware
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
A reflected cross-site scripting (XSS) vulnerability in the Fireware OS Web UI enabled execution of malicious JavaScript in the context of an authenticated management user's browser when they click on a specially crafted link.
Affected products
- WatchGuard Fireware: from 12.7, before 12.11.8 (fixed in 12.11.8); from 2025.1, before 2026.1.2 (fixed in 2026.1.2)
Published 2026-03-03. Last modified 2026-08-10.